← All articles
Guide3 March 20268 min read

AI in mid-sized businesses: where it really saves time and where it does not

Language models can save measurable time in everyday office work, but by no means everywhere. This article gives a sober assessment of which tasks are worthwhile today, which data may go into which tools, and how to scope a first project so that you can verify the benefit at the end.

This article provides general information and is no substitute for legal advice. For binding answers on your situation, consult a law firm.

What we are talking about: a tool, not a strategy

When people talk about AI in the office today, they almost always mean large language models: programs trained on very large volumes of text that have learned to summarize, rephrase, and generate text. They are known through chat interfaces such as ChatGPT or Microsoft Copilot. One point is decisive for putting them in perspective: a language model calculates which wording is likely to be a good answer. It does not look anything up in a verified database. That is why it is strong at language and structure and weak wherever guaranteed accuracy matters.

This leads to a simple practical yardstick: you do not introduce AI as such; you check task by task whether a language model gets you to a usable draft faster than a person alone. This sober view protects against the two typical mistakes: the expensive large-scale project without a clear purpose, and the blanket ban that drives employees into secretly using private accounts without any rules.

Four areas where AI saves time today

The most reliable benefit is with documents. Language models condense long minutes to a single page, turn bullet points into a proposal text, and draft work instructions, job advertisements or translations. The rule always stays the same: the model delivers the raw draft, and a person with subject knowledge reviews, corrects, and takes responsibility for the result. If you accept this division of labor, you can save noticeable time on text-heavy tasks.

The second area is email drafts. Standard replies to recurring inquiries, the factual wording of an unpleasant message, a reply draft from three bullet points: the saving per email is small, but the total is significant at high volumes in sales, purchasing or customer service. It is important that drafts are read before sending, because the model knows neither your customers nor your commitments.

The third area is knowledge search in your own documents. The underlying method is called RAG, short for Retrieval Augmented Generation: the tool first finds the relevant passages in your stored documents and then formulates an answer with source references. This makes manuals, contracts, maintenance reports and old proposals searchable by question. The prerequisite is that the documents exist digitally and are reasonably organized, and that access rights are correct. A tool that shows every document to every user is not a search, it is a data protection problem.

The fourth area is recurring processes: sorting incoming mail by topic, capturing details from invoices or delivery notes and transferring them into your own system, converting free text from forms into a fixed structure. Here, classic automation with fixed rules usually works together with a model that handles only the fuzzy part. This area often produces the most stable savings, because the process runs daily and the result is easy to check.

Where AI regularly disappoints

The most important weakness has a name: hallucination. It means that a language model invents plausible-sounding but false statements, for example legal provisions, standards, product data or sources. That is why it is not suitable as the sole source of information on legal, tax, and contract questions, or anywhere a wrong number gets expensive. Review by a qualified person is not an optional step but part of the process.

Other typical disappointments: complex calculations are unreliable. Without a connection to your systems, the model knows nothing about your internal processes. Very specialized expertise with little published literature is reproduced incompletely or incorrectly. Keeping long documents consistent is difficult for models. And a tool only delivers current information if it has a built-in internet search.

The biggest disappointment, however, comes from wrong expectations. A language model rarely replaces an entire position. Realistic gains are minutes per task, which add up to hours per week for frequent tasks. And an unclear process does not become clear through AI: if nobody can say exactly how a process runs today and what a good result looks like, any automation lacks its foundation. In that case, process work is the first step, not buying tools.

Data protection: which data may go into which tool

Most AI tools run as cloud services, meaning on the provider’s servers and not on your premises. The first question is therefore what happens to your inputs. Free consumer versions of many services reserve the right to use inputs to improve their models and do not offer a data processing agreement. A data processing agreement, in German an Auftragsverarbeitungsvertrag or AVV for short, is the contract that the European General Data Protection Regulation (GDPR) requires when a service provider processes personal data on your behalf; it obliges the provider to use this data only according to your instructions. Personal data, meaning any information that can be linked to a specific person, such as names, contact details or personnel records, therefore does not belong in tools without an AVV.

A practical approach is to divide data into three classes. Class 1: public and non-critical content with no personal reference and no confidential business reference, for example the draft of a general website text; it may go into any approved tool. Class 2: internal business data such as calculations, contract drafts or plans; it belongs only in business versions with an AVV, with a training opt-out, meaning the contractual assurance that inputs are not used to train the models, and preferably with processing in the EU. Class 3: personal and especially sensitive data, for example from personnel files, health records or bank documents; it goes into a cloud tool only after explicit review, and in case of doubt not at all. Write these rules down on one page and make them known throughout the business, otherwise you get exactly the silent, unregulated use you want to avoid.

For very sensitive data there are local alternatives: openly available language models that run on your own hardware or at a German data center operator, so that the data does not leave your environment. The honest assessment: smaller local models do not consistently reach the quality of the large cloud services, and operating them needs someone to take care of everything from hardware to updates. Local setups are worthwhile mainly where Class 3 data is to be processed or where cloud services are ruled out for other reasons.

In addition to the GDPR, the European AI Regulation (the AI Act) now applies and is becoming applicable in stages. For typical office use, the most relevant points are that companies using AI systems are expected to ensure that their staff have sufficient knowledge of how to handle them, and that certain types of application are prohibited or strictly regulated. For normal text assistance, the obligations are manageable; anyone who wants to use AI in personnel decisions or assessments of people should have that reviewed legally beforehand.

The first project: scope it small and measure honestly

Choose the first task by five criteria: it occurs frequently, at least several times a week. It is text-heavy. The result can be checked quickly. A mistake can be corrected before damage occurs. And it works without Class 3 data. Good candidates are meeting minutes, reply drafts in customer service, or summaries of technical documents. A poor first candidate is anything related to job applications and personnel, because personal data and legal questions are immediately involved there.

The project only becomes measurable with a baseline. Before you start, record how many cases occur per week and how many minutes one case takes today. Then two to five employees test the tool over a fixed period of four to eight weeks. Afterwards you measure again, including the time for reviewing and correcting the AI drafts. Define in advance the value at which the project counts as a success and when you will stop. Without a baseline, all you have at the end is a gut feeling, and gut feeling is no basis for a wider rollout.

Much of this is doable without external help: testing a business version of a chat tool, writing down the data rules, running the pilot and measuring the results. Support from your own IT or a service provider makes sense as soon as your own document repositories are to be connected, because then filing structure and access rights have to be correct, as soon as interfaces to merchandise management or ERP systems are created, meaning the software that manages orders, inventory, and accounting, or as soon as local models are to be operated.

How to tell when only the AI label is being sold

The first warning sign is vagueness on simple questions. Ask every vendor: which model works in the background? Where is our data processed? What happens to our inputs? How are errors detected and corrected? Anyone who evades these questions or offers only buzzwords may be selling a thin interface on top of someone else’s standard service. That can be acceptable, but it should be stated openly, because it determines your dependency and the fair value in return.

Other warning signs: firm savings promises before anyone has looked at your processes. No test access and no small pilot, but a long contract term from day one. No clear answer to the questions about the AVV, the place of processing and the training opt-out. And the AI label on features that have long existed under other names, for example simple if-then rules or classic text recognition.

Conversely, there are good signs: a reputable vendor starts with your tasks instead of its product, points out limitations unprompted, accepts a small pilot project with agreed metrics, and provides data protection documentation without being asked. If you go through these points one by one in a first meeting, the vendor market sorts itself out surprisingly quickly.

The short version

In mid-sized businesses, AI saves time where frequent, text-heavy, and easily verifiable tasks occur: with documents, email drafts, searching your own knowledge and recurring processes. If you define data classes, start small and measure the benefit against a baseline, you avoid the typical missteps and recognize misleading labeling early. Ruknova supports you with selecting suitable tools, assessing data protection and scoping a first pilot project, from Schwerin, Germany-wide.