KI FÜR MÜNCHEN AI adoption. Done right.

GOVERNANCE · 6 July 2026 · 8 min READ

Adopting AI: Why Governance Comes Before Tools

Most AI adoptions begin with licences and end in frustration. Why the order of operations decides success — and what the road to an AI-first company actually looks like.

There is one sentence we hear in initial conversations more often than any other: “We know we need to do something with AI — but we don’t know where to start.” And there is one answer that almost everyone has already tried: buy licences, hand out accounts, hope.

Twelve months later, the result almost always looks the same. A few colleagues use the tools enthusiastically, most not at all. Nobody knows which company data has ended up in which systems in the meantime. Two pilot projects have fizzled out. And it dawns on the management team that they have no answer to the question “Who is actually liable if something goes wrong here?” AI was introduced — but nothing has improved. Some things are more complicated.

The flawed assumption: AI as a tool purchase

The fault lies neither with the tools nor with the staff. It lies in the assumption that adopting AI is a procurement exercise: you buy something, distribute it, and then it gets used. That is how it works with office software. With AI it does not — for one simple reason:

AI amplifies what is already there. A clean, documented process with structured data becomes faster, more consistent and better with AI. A chaotic process with scattered data and unclear responsibilities becomes — chaotic faster. Layer AI over broken processes and you automate the chaos. A difficult system only becomes more difficult with AI.

That is why the order of operations is not a detail but the decision on which everything hinges: First optimise the processes for AI, then introduce AI. Never the other way round.

The three pillars without which nothing scales

A single AI use case can be improvised. An organisation in which AI creates value broadly and durably needs structure — on three levels at once:

AI management. Who decides which AI application is introduced? Who signs off, who is accountable, who monitors? Without this steering, every rollout remains a matter of chance — with it, it becomes repeatable. The international standard for this is ISO/IEC 42001, which describes precisely this management system.

Data management. AI is exactly as good as the data it works on. Data quality, data flows, access rights, currency: fail to tidy up here and you get an AI that confidently quotes from outdated records. The most uncomfortable and most frequently skipped part of any adoption — and the decisive one.

AI governance. The rules: what is permitted, what is not? Which application falls under which risk class of the EU AI Act? How are GDPR, trade secrets and employee co-determination upheld? Governance is not a brake — it is what turns “let’s give it a try” into “we may, we can, we do”.

If one of the three pillars is missing, the adoption topples sooner or later. Almost every PoC graveyard we have seen can be traced back to a missing pillar.

What the road actually looks like

From these pillars follows an approach that sounds less spectacular than any AI vision — and works precisely for that reason:

1. Audit instead of activism. It begins with an honest stocktake: Which processes actually exist (not: which are in the manual)? What is the state of the data? What are staff already using today — officially and unofficially? Which rules are missing? The result is not a vision but a gap list with priorities.

2. A shared target picture. Where should the journey go — and how far? Not every company needs the full build-out straight away. The target picture is defined jointly and broken down into stages, each of which delivers value in its own right. How far to go is the customer’s decision — the stages are levels of build-out, not a compulsory route.

3. Plannable, measurable individual steps. No heroic effort, no big bang. Every step has a defined outcome and a metric by which it is measured. Whatever does not prove itself is corrected before it becomes expensive.

4. Bringing people along — department by department. The best structure fails if teams are expected to learn it themselves alongside the day job. That is why training happens department by department: with concrete use cases for precisely their work, with briefing, implementation and ongoing support. The learning curve is carried by the partner, not by the overstretched employee.

And the tools?

They do come — right at the end, and by then their selection is suddenly straightforward. Once processes, data and rules have been clarified, any tool decision can be made in a week, because the requirements are on the table. Without that clarity, you spend months debating vendors — while in truth answering the wrong question.

The goal of all this, incidentally, is not “a bit of AI”. The goal is an AI-first company: an organisation in which AI works natively in every process — transparent, tested, deterministic, with humans at the decision points. We know this is achievable, because we run our own organisation in exactly this way.

The first step towards it is not an investment decision but an assessment of where you stand. Our readiness check delivers it in five minutes — free of charge, with no data transfer and no sales call afterwards.

This article was created with AI assistance and editorially reviewed under the responsibility of Stephan Walkowiak. See our AI transparency statement for details.

NEXT STEP

Apply this to your company?

In an initial consultation we discuss what this topic looks like in your specific case — honestly, even if the answer is "not yet".