Introducing Claude in your company: the five decisions before the first euro

By Ralf Schmidt | 7 August 2026 | Tech Corner
Since 2 August 2026, large parts of the EU AI Act have applied: the transparency obligations under Art. 50 are in force, and the Federal Network Agency has taken over market surveillance for AI in Germany. At the same time, the Digital Omnibus has postponed the strict high-risk obligations by more than a year. Anyone deciding as a managing director, IT lead or data protection officer on the introduction of an AI assistant must be able to tell the two apart.
Claude is the AI assistant of the US provider Anthropic and currently the tool under discussion in many companies. The following five decisions, however, are largely tool-independent — anyone introducing Microsoft Copilot or Google Gemini instead faces the same questions. All five fall within the first six weeks, long before IT starts building. And when a rollout stalls later, it can almost always be traced back to one of these five having been made too late, or not at all.
1. Consumer plans are out — and are already in the building
Claude Free, Pro and Max come without a data processing agreement (DPA), and inputs may feed into model improvement. This removes the basis for two different kinds of data: for personal data, the contractual basis required by Art. 28 GDPR is missing. For trade secrets without personal reference — calculations, bid strategies, source code — it is not a GDPR issue but a matter of trade secret protection and your customer contracts. Both lead to the same result: not usable in operations.
The uncomfortable part comes first. Assume it is already happening in your company. Not out of bad intent, but because someone in sales noticed that draft proposals get done faster. This unofficial use via private accounts — “shadow AI” — is the actual starting point, not a greenfield.
The first concrete step is therefore not a tender, but an inventory of actual usage plus a written instruction prohibiting private AI accounts for company data.
Sequence matters: a ban without an available alternative creates more shadow AI, not less. The ban and the official environment must arrive at the same time.
2. The access route determines which assurances you can give at all
A commercial plan is mandatory. Which one depends on your protection requirements.
| Access route | DPA | Zero Data Retention | EU data processing | Suitable for |
|---|---|---|---|---|
| Claude Free / Pro / Max | ✗ | ✗ | ✗ | business use: no one |
| Claude Team | ✓ | ✗ | ✗ | small teams without sensitive data |
| Claude Enterprise | ✓ | optional | ✗ (US/global) | office use with SSO and audit logs |
| AWS Bedrock (EU regions) | AWS DPA | ✓ | ✓ | elevated protection needs, EU requirement |
| Google Vertex AI (EU regions) | GCP DPA | ✓ | ✓ | alternative to Bedrock |
| Claude via Microsoft 365 | via Microsoft | – | ✗ (US) | M365 shops, lowest barrier |
Zero Data Retention (ZDR) means that inputs and outputs are not stored by the provider — the prerequisite for processing sensitive content at all.
The point that regularly gets lost in sales conversations: Anthropic advertises regional data residency for Europe. But it is delivered through the cloud providers, not through the direct Anthropic contract. Neither claude.ai nor the Anthropic API offers EU data residency; there, processing runs on US infrastructure.
So anyone who wants to assure the works council, a customer or a supervisory authority of EU processing needs the route via AWS Bedrock (including Frankfurt, Ireland, Paris) or Google Vertex AI with European endpoints. That is an architecture decision, not a contract clause — and it has a price: the familiar claude.ai interface is not available there, you need your own chat front end.
For companies already running on Microsoft 365, there is a third route. Anthropic models are available as a selectable model in Copilot Chat, the Researcher agent, Copilot Studio and Office agents; in Microsoft Foundry they are now generally available. Employees stay in Teams, Word and Outlook, administration runs through familiar Microsoft tooling — by far the lowest barrier to entry.
The catch: for Claude models, Microsoft does not yet offer a European data zone. Processing takes place outside the EU Data Boundary, and Microsoft has therefore disabled the feature by default for tenants in the EU, EFTA and UK; an administrator must deliberately switch it on. A European Foundry option has been announced, but without a date.
This results in a two-track setup: non-critical and properly pseudonymised content via the convenient Microsoft route, sensitive data via the EU route. That is a convenience decision, not a compliance one. Anyone who wants to avoid the dual architecture runs everything through Bedrock.
3. The works council belongs in week 3, not week 14
Of the projects we get to see after the fact, this is the most common avoidable breakdown.
Section 87 (1) no. 6 of the German Works Constitution Act gives the works council an enforceable co-determination right for technical systems capable of monitoring behaviour or performance. AI logs show who asked what and when. That meets the criterion — regardless of whether you ever intended to evaluate it.
A works council that has been bypassed can enforce a shutdown via interim relief. Two to six weeks of proceedings, project standstill included. The technology sits there finished, and no one is allowed to use it.
The remedy costs almost nothing: inform early, commit to anonymised evaluation, contractually exclude individual usage monitoring. In most cases the works council is not an opponent, but someone who needs a reliable commitment in order to agree.
A framework works agreement on “AI” should cover at least eight points: scope, a positive list of permitted use cases per user group, an explicit ban on performance monitoring and automated decisions about employees, data rules, transparency towards staff, proof of training as an access prerequisite, the council's audit rights, and an amendment clause for future systems.
A detail from practice: anyone running Microsoft Copilot and Claude in parallel — as many mid-market companies do — should write one shared AI rulebook for both tools. That saves the duplicate works council and data protection discussion and prevents two silos with different rules.
4. Training is an access prerequisite, not a side programme
The AI literacy obligation under Art. 4 of the EU AI Act has applied since 2 February 2025. The Digital Omnibus softened it in the summer of 2026: the duty to ensure a certain level of competence became a duty to promote it. It was not deleted — providers and deployers must still take measures to develop the AI literacy of their staff.
In practice this changes little, because the hard rule has proven itself for another reason anyway: no training record, no account. It is less a compliance instrument than the most effective lever you have for adoption. And it incidentally delivers exactly the evidence Art. 4 requires.
One training for everyone does not work. A developer needs API security, awareness of prompt injection and review discipline. A case handler needs prompt basics and clear data rules. A managing director needs governance, liability questions and the insight that she has to use it herself for the others to follow. As a guideline: two hours of basics for everyone, four hours extended for developers, two hours of governance for the leadership level.
5. Block the high-risk use cases — then the deadlines work for you
Do not release recruiting assessment, person-level HR analytics and automated decisions about people at all for now. This single decision removes the entire high-risk part of the AI Act from your project — the obligations then simply do not apply.
This is so effective because this is where most has moved in recent months, and correspondingly many half-truths circulate. The state of play in three points:
Postponed, but decided. The Digital Omnibus entered into force on 27 July 2026 as Regulation (EU) 2026/1744 — following approval by the European Parliament in June and by the Council at the end of June 2026. The high-risk obligations under Annex III, including for recruiting AI, therefore only apply from 2 December 2027; high-risk AI embedded in products follows on 2 August 2028. That is applicable law, not an announcement — you can plan on it.
Supervision is in place regardless. Under the German AI market surveillance and innovation promotion act, the Federal Network Agency is the central market surveillance authority and national contact point. It has explicitly named the use of AI in human resources, among others, as a focus area. An incident in this area therefore attracts more attention today than a year ago — and can discredit an entire rollout project, even if it was not formally unlawful. The postponed deadline changes nothing about that.
The labelling obligation affects you less than you are currently reading. The transparency obligations under Art. 50 have applied since 2 August 2026. The bulk of them targets the providers of the systems, not their business users — and the frequently cited fine of up to 15 million euros or 3 percent of global annual turnover mostly points there too. As a deploying company you are mainly affected in three cases: if you operate a customer-facing chatbot and must disclose that the interaction is with an AI; if you use deepfakes; or if you publish AI-generated text on matters of public interest. A general obligation to label every AI-assisted proposal email does not follow from this. For providers of generative systems already on the market before the cut-off date, a transition period for machine-readable marking of synthetic content runs until 2 December 2026.
A labelling rule nevertheless belongs in the written instruction — not because of Art. 50, but because customer and framework contracts increasingly contain their own disclosure clauses. Check that against your contracts, not against the legal text.
The operational backbone: the data category traffic light
The five decisions concern management. Employees need a translation, and there is exactly one tool that works in practice. One page, understandable for everyone, on the intranet and as a notice:
- Green – public or internal without personal reference: market data, product information, your own texts, anonymised case examples. Freely usable in the approved environment.
- Yellow – confidential but pseudonymisable: customer cases, contracts, internal code. Only after pseudonymisation and only in the company environment.
- Red – personally sensitive or strategic: clear-text data of customers and applicants, salaries, health data under Art. 9 GDPR, M&A documents, production database extracts. Only in a ZDR environment by authorised roles — or not at all.
The traffic light only works if the yellow rule is easy to follow day to day. Add a short pseudonymisation guide with examples (“Müller GmbH → Customer A”). And put it on record: the line runs at pseudonymisation, not at gut feeling.
Safeguarding is not yet impact
The five decisions ensure that your project is not stopped. Whether it pays off is decided afterwards — and that is where the most common failure in execution lies.
It looks like this: the technology is in place, but there are no templates and no concrete use cases. Users try something once, are moderately impressed and never come back. Three remedies have proven effective.
Specify two concrete quick wins per department instead of saying “give it a try”. Sales: proposal and email drafts, structuring call notes. Controlling: condensing reports, having tables explained. Project management: turning meeting notes into task lists.
Appoint champions — roughly one per 30 to 50 users — as the first point of contact in the department. That relieves IT and lowers the barrier far more than any hotline.
And measure real usage instead of distributed licences. As a workable rule of thumb, someone has arrived in everyday practice if they deliberately work with the tool around 30 times in four weeks. Anything below that is curiosity, not habit.
The timeline
For a company with around 500 employees, 16 to 20 weeks is realistic: stocktaking in weeks 1 to 2, legal and contractual work including the works council conversation in weeks 3 to 6, technology with SSO, automated on- and offboarding and audit logging in weeks 7 to 10, pilot operation in weeks 11 to 14, then a department-by-department rollout.
The fact that leadership opens the pilot is not a courtesy. There are two sober reasons: executives who use it themselves measurably drive adoption — and their data risks from strategy, M&A and HR topics require the protected environment to be in place before anyone else's anyway.
What stands out is how little of this is technology. Four of the five decisions are made in contracts, conversations and written instructions — long before anyone configures a system. Precisely for that reason they are so easy to overlook and so expensive to catch up on.
Legal status: 7 August 2026. This article does not replace legal advice; the interpretation of Art. 50 of the EU AI Act in operational use is in parts not yet conclusively settled. Product details such as prices, ZDR conditions and the availability of EU regions change at short notice — check the current provider documentation before signing a contract.
ZEMID GmbH supports mid-market companies with IT transformation and AI strategies — from the access route decision through the works council conversation to the rollout. If you are currently stuck at one of these points, talk to us. zemid.de/contact
