Erfolgreich bleiben im KI-Zeitalter
KI-Business Transformation
Künstliche Intelligenz verändert gerade jedes Unternehmen, ganz egal, ob es sich dafür oder dagegen entscheidet. Selbst eine Firma, die sich gegen die Technologie entscheidet, sieht sich dennoch mit Software und Anlagen konfrontiert, die KI integriert haben. Und nicht wenige Mitarbeitende nutzen ohne Zustimmung auf eigene Faust KI-Chatbots, notfalls auch auf persönlichen Geräten, ohne jedes Training. Und manchmal hat auch die Konkurrenz plötzlich einen Vorteil, weil sie KI in ihren Produkten oder Geschäftsprozessen nutzt. So oder so, man kann diesem Thema nicht entkommen, man kann nur wählen, wie man sich ihm stellt. Und genau dadurch definiert man die KI-Identität einer Organisation.
“Herr, die Not ist groß!
Die ich rief die Geister,
Werd ich nun nicht los.”
The Sorcerer’s Apprentice, Johann Wolfgang von Goethe (1797/98)
What is your AI Identity?
9senses has defined three archetypes of AI identities companies can have. Learn more by clicking on the tab or take our 5-minute test to find out where your company stands.
AI Hesitant
The AI Hesitant does not actively engage in AI, but AI is still creeping in by third-party tools and unauthorized AI use by employees.
AI Sprinter
The Sprinter embraces AI without hesitation - and might reap some short-term benefits but endangers control over the business long term.
AI Wise
An AI Wise company finds the right balance between adopting AI and maintaining control. Its foundations are sound, and investments targeted.
From the inside, the Hesitant position feels safe. No budget is burned on hyped AI that is more likely to fail than to succeed, no risky projects are started, and employee use of AI chats are blocked.
Unfortunately, the defining property of AI is that it does not wait for an invitation. It just arrives. The software you already pay for adds AI features release by release, and your people are ahead of you: in the largest global study on workplace AI to date, only 40% of employees said their workplace has any policy or guidance on generative AI, while almost half admitted to using it in ways that break company rules, including feeding sensitive company information into free public tools. 57% said they hide their AI use altogether.
There isn't a "no-AI" option
While not deciding anything on AI or even actively saying "NO" is possible, you are still fully exposed. The EU AI Act is in place, and a purchased product or an illegitimately used chatbot can put you in scope for rules you never read.
If you contacted us tomorrow, our advice would not be an AI project. It would be to build the AI Foundation and AI Baseline to cover you. It would mean training your senior management to build some basic understanding of AI. It would mean an inventory of what is already in your company, estimating the exposure, defining rules and boundaries, and setting up minimal training and support for employees who are very likely already using AI behind your back.
Take the AI Identity test and find out which company type yours is - or schedule a 15- minute call to learn more about how we can help.
The price
AI Hesitants pay
You carry the exposure without most of the benefits. You pay for AI inside your tools whether it is governed or not.
One pasted contract, one confidently wrong answer sent to a customer, and the incident lands on an organization with no rules, no owner and no routine. But full responsibility. And when engaging becomes unavoidable, you start under pressure instead of by choice.
FAQs for AI Hesitants
We deliberately decided against AI. Isn't that a valid strategy?
Deciding against your own AI applications is entirely legitimate, and we often advise companies to do just that. Deciding against AI, while it creeps in through tools and illegitimate use by employees, is impossible. The exposure exists whether you engage or not, the only choice is whether it is covered.
Can't we just block the tools?
Blocking is the worst possible decision. It doesn't remove tool use, it just shifts it outside the visible area. Teams or individuals, are under pressure to deliver output, will simply switch to AI on private devices, which often means lower-quality models, privacy and confidentiality issues, and a complete loss of control over what is going on. Approved alternatives, combined with training and clear rules, reduce unauthorized use far more effectively than a ban.
What is the very first step?
The first step is learning about AI, followed by measuring, creating an inventory of where AI already lives in your organization. This takes days, not months. Everything else builds on this.
The Sprinter is visibly the innovator, is ahead of the curve, by using the latest technology and possibly scoring some quick wins. Some of those gains are real, maybe well-used AI increases staff efficiency and reduces hiring needs.
But then, still a large number of generative AI pilots produce no measurable return, and, increasing.ly, companies are abandoning AI initiatives. The pattern behind these numbers is always the same: applications are added faster than the foundations that keep them controllable, ranging from appropriate testing to governance.
Stealing from their own future
The deeper cost compounds: in a 2026 BCG study, C-level interviewees observed deskilling among their employees who heavily rely on AI-generated output; and complained about glossy work that was shallow in content. That's a key AI feature. Managing this, while steering the company towards efficient AI use, is hard work.
At the same time, some savvy companies reduce entry-level hiring, while managing AI use productively. They will pay the price in the future, when nobody in the organization has learned how to do things at the core of the business, and how to review and judge AI outputs. We call it the AI Apprenticeship Debt Curve. Quick gains now, and losses arriving later.

If an AI Sprinter contacted us tomorrow, our advice would be to pause AI introductions in order to catch up on a solid foundation before the next AI launch; and to establish a solid cross-company baseline that guides AI use and adoption.
The price
AI Sprinters pay
Every AI-based application added on this footing raises exposure faster than oversight and control can catch up. Incidents land on an organization that is fast but unprepared.
The risks include a high cost for abandoned AI projects, uncertainty about AI impact on the business,
Questions AI Sprinter might ask
We are seeing real productivity gains. Why change anything?
The gains are not the problem; but the uncovered exposure underneath is. Reducing that exposure doesn't mean giving anything up, it means being able to keep what you have gained and build a solid foundation that outlasts the short-term wins.
Won't governance slow us down?
The evidence points the other way. The small number of initiatives that generate measurable long-term value are the scoped ones with a defined purpose, clear success criteria, early fail gates, and good governance. Building the harness that doesn't let you cede control to AI is a small cost compared to the risk.
Which of our running applications should we review first?
The highest risk lies in generative AI and Machine Learning applications where the output doesn't undergo regular human validation, and where continuous testing isn't a built-in feature. That is precisely where AI confidently makes the errors nobody discovers.
Being AI Wise doesn't mean a choice on how much AI a company adopts. It rather means that it is prepared for AI. The baseline is to ensure that all employees - from top management to everyone with potential exposure, understand AI well enough to see its benefits, limitations, and risks.
Further, it means understanding where AI already lives, understanding the risks and guiding them, particularly when it comes to general use of GenAI chatbots to solve business problems. It is better to provide solid tools rather than have employees use AI anyway under the table, with all the risks this entails. Lastly, there is a solid governance layer required, ensuring that AI can't quietly damage the business, and that AI application are tested the way they should be - continuously.
Balance is maintained, not reached
Being AI Wise has no finish line. AI models change, vendors add features, prices and terms move, regulations change, people come and go. With each of those changes the exposure drifts, so coverage has to be re-measured and grown with every new application. That is why we describe AI transformation as a control loop rather than a journey. An AI Wise company is staying in that loop.
Let us know if you want to become AI Wise - it's easier than you think.
What AI Wise companies win
AI wise companies engage with Artificial Intelligence carefully, but in a way that their business foundation and their long-term success is never in danger.
By laying a solid AI foundation and defining a baseline for AI use, they ensure proper adoption and governance, making most AI initiatives fail early or succeed.
It is based on knowledge about AI, its benefits and risks, and a clear governance framework around it.
Questions we get asked
Is AU Wise just a polite word for slower?
AI Wise says nothing about adoption speed. A company can deliberately introduce AI in places where it is meaningful or stay away from AI outside of generic employee support. Both can be wise. It's the choice you have.
Do we need a Chief AI Officer?
Not necessarily. But you need AI literacy on all management levels, and you need clear decision-making authority about AI initiatives across the organization. The setup is secondary, but competence and agility matter.
How do we stay on top of AI change?
This is challenging, as AI models change almost daily under the hood, and AI capabilities are introduced in more and more products, from software to equipment. These changes need monitoring, and regular reviews, as well as a completely different testing approach: with AI, every day is "release day".
To become AI Wise, where you're neither run over by AI changing your reality, nor are among those who aimlessly engage, it is imperative to develop a thorough understanding of Artificial Intelligence, its benefits and its limitations, and begin applying it cautiously and methodically, with the necessary guardrails and a way to rapidly adjust as it changes.
AI Wise building blocks
Three layers of engaging with AI. The first two are essential for all organizations, even if they don't start their own specific AI initiatives. The third one .-. AI Substance - is optional.
AI Foundation
The AI Foundation is what keeps you on solid ground. It includes many elements, such as a strategic decision on AI use, basic governance and boundary rules, combined with the necessary organizational and structural elements that allow you to stay on top of change AI brings to your world.
AI Baseline
The AI Baseline layer covers the almost unavoidable parts of active AI use, those that create benefit or damage for the entire organization. It includes training, particularly on the use of generic tools like Copilot or LLMs for creative work, and it covers the necessary governance and documentation rules related to that AI use.
AI Substance
The AI Substance layer is entirely at your discretion. It contains all the specific AI-driven applications you introduce, as parts of your products or business processes. Individual initiatives aimed at improving product or processes sit here. It is the one that is never mandatory and can be scoped carefully one by one where AI truly adds value.
Four key elements are at the core of an AI Foundation.
Strategic position
This decides where AI belongs in your organization and where it doesn't. It is built based on the AI literacy of senior management and defines what strategy the company wants to follow on AI, and how this strategy is continuously revised as the technology involves. It defines the guiding principles of AI adoption.
Governance and ownership
This mandatory layer defines the rules for engaging with AI on an organizational level. It defines as to where the decisions about "yes" and "no" sit, and how they are managed. There is no hiding behind "the AI did it", and courts and customers forgive machine failure less readily than human error, not more.
Rules and boundaries
The regulatory framework - for example the EU AI act and data protection laws - are only the floor of what matters. Most boundary decisions are business decisions: which data may go into what tools, which AI uses and decisions need to be documented; what is off limits.
Risk Management
Risk management starts with understanding exposure - an inventory of AI tools that have quietly entered your business without you asking for them. It continues to questions of resilience - what happens if you had to replace or switch off a tool tomorrow, would operations continue? And another important question: how does the organization develop and maintains its skills with increasing AI use?
What happens without an AI Foundation?
Without a foundation, your organization is built on quicksand, and everything above it is in danger.
The first serious incident then defines the future of your organization, because you missed defining the future yourself.
AI Foundation FAQs
Is this a big compliance project?
No. At the core of a working AI Foundation is education, an AI inventory, a strategic position, boundary rules and a risk management plan for AI. For most companies that can be completed within a few weeks.
We already have IT governance. Isn't that enough?
AI is fundamentally different from traditional IT, which is deterministic, its decisions can be traced and reproduced. AI is built on the opposite promise, reacting flexibly without a fully reproducible logic. That breaks the assumptions your existing governance relies on, which is why AI needs its own rules and testing protocols.
What does the EU AI Act require from us right now?
As of today, you have to refrain from the prohibited practices, including emotion inference at the workplace, even inside products you bought. From December 2027 onwards, you have to follow all high-risk obligations, if your AI uses fall under them. Since July 2026, literacy is encouraged but no longer mandated.
How do we find the AI already in use?
Ask, without blame, so people answer honestly. Then read your vendors' release notes: much of your AI arrived through updates to software you already had. Keep the resulting inventory alive; it is the measuring step everything else builds on. And - this inventory has to be re-created every few months.
The AI Baseline defines tools and rules that apply to the entire organization. While you theoretically can refrain from providing AI tools, doing so risks employee use in a way that poses much greater risk to your organization. It is thus highly recommended to close unauthorized use by providing a high-quality alternative.
Approved tools
This defines a toolset employees can use with confidence, curated for your actual work and your data protection needs. This is the single most effective control there is: people reach for unauthorized tools far less once a meaningful approved alternative exists. It is important to continuously evaluate these tools to not fall behind and have clean upgrade and testing paths as they change on their own.
AI literacy
Employees who don't know how AI works and how to use it are bound to produce glossy content that is shallow. This is about knowing how to use these tools, but even more in understanding their failure modes: answers that are confidently wrong exactly where you cannot check them, or evaluations that change every time you ask. People who know create better results with AI and stay in control.
AI usage rules
With a solid AI toolset in place, enforceable rules are typically accepted by employees. These rules define what may go into where, what is off-limits, and how AI use is checked and documented.
The last two are important above all. Wherever important business output is created - no matter if used for internal decision-making or in a customer-facing role - this use must be documented and the findings must be independently validated, not simply shipped into any decision-makin process relying on it. The final judgment has to stay with a human. This doesn't just protect you legally, but it also maintains the skills an organization needs in the long run.
Oversight
A current inventory of the AI in use, including what individual employees adopted on their own, and visibility into adoption, quality, incidents and change. Not surveillance; bookkeeping. You cannot cover what you cannot see.
What happens without an AI Baseline ?
Without actively shaping the AI Baseline, employees will continue to use AI in an unguided and unsupervised fashion. They are likely to put their confidential work data into their private devices, or use tools embedded into their daily work tools in a way that can cause damage.
The first serious mistake that will damage the company will be made in good faith, by someone who was never taught how AI works, was never told the rules, and what to watch out for.
This makes it your mistake, not theirs.
AI Baseline FAQs
Which tools should we approve?
The ones that match your data protection requirements and the work your people actually do. We are vendor-independent and take no commissions, so our answer can differ per company, and often the answer is "fewer than you think".
How much training is enough?
Since tools change rapidly, a base training with short re-trainings every few months is the best format. Everyone who touches AI needs to learn how to use its current capabilities, how to prompt it, but most importantly what it can do and where it fails.
How do we find the AI already in use?
Ask, without blame, so people answer honestly. Then read your vendors' release notes: much of your AI arrived through updates to software you already had. Keep the resulting inventory alive; it is the measuring step everything else builds on. And - this inventory has to be re-created every few months.
Substance is where AI is supposed to create value specifically, in a product or a business process. This layer is completely optional, but in many cases, it offers great promise. No matter if this relates to customer interactions, operations or data and knowledge management. AI can actually bring benefits.
Carefully admit case by case
The most important aspect is a clear process, with many early gates that avoid experiencing what many companies experience: prototypes that should never have gone into production, releases that don't hold up beyond a carefully curated set of test cases, solutions quietly deteriorating after their launch.
Testing isn't a gate, it's a loop
Contrary to regular IT applications, where testing typically is part of a release process, AI solutions have no final stable state. They constantly need to be evaluated against their objectives, whenever something changes. And changes are manifold - a new model or changing context windows on the vendor side, or different inputs from newly ingested data, just t o name a few.
Where this goes wrong
Applications adopted for the feeling of keeping up. Demos that never met a real workflow. Success that nobody defined, so failure that nobody can call.
That is the road to the statistics: the large majority of pilots without measurable return, and portfolios abandoned wholesale a year later.
Questions we get asked
How many AI initiatives should we run?
As many as your coverage supports and your portfolio justifies. For most companies the right number is smaller than the ambition, and the initiatives that remain are the ones that reach production.
Build or buy?
Case by case, and we have no stake in the answer. What we do insist on either way is the hybrid design: AI plus tested logic plus a human path, because that is what we see working in production.
When should an application be retired?
When the case that admitted it no longer holds: the model changed, the price changed, the workflow changed, or the results never met the criteria. Monitoring exists so that this is noticed, not discovered.
AI transformation has no finish line
Classic transformations run as projects: analyse, design, implement, done. AI does not hold still for that. Models, vendors, prices, laws and people move while you plan. The familiar disciplines of transformation sit inside a control loop: Foundation sets strategy and control, Baseline makes it everyday practice, and Substance creates measurable value. The Hesitant never starts it turning. The Stormer turns only part of it. The Wise turns all of it, at a pace it chooses.
The 9senses AI playbook is different
The large transformation consultancies have arrived at two conclusions we agree to: most of the work in transforming a business is related to people and process, not technology, and that transformation has no end state. Their own research adds a third: the overwhelming majority of AI pilots never produce a measurable return.
Where we part ways is the goal. Our primary objective is AI resilience, not adoption. Many assume that more AI is the destination. Our destination is balance: coverage that tracks your real exposure, and exactly as much AI as you deliberately choose. Sometimes that is a lot, but sometimes this can be very little. A vendor-independent advisor can say that without hesitation.
Find your AI Identity
Answer the 15 questions in our AI Identity test takes, completely anonymous. The result gives you a clear starting point. Once you see it, you can decide what to do with it (download it, share it with us for a conversation, or stop there). It is free without any obligation. Or skip the test and talk to us directly.
What is your AI Identity?
Every company has an AI Identity, revealed by how it responds to the AI exposure it already has. Fourteen statements, about five minutes, and you will see where your company stands today. Your answers stay in your browser and are not stored or transmitted.