AI Readiness Audit · Prioritise Use Cases · Vendor-neutral

Before you build, you sort.

Use-case list, data map, AI Act filter. Written. Mandate-specific.

Audit for B2B industry firms taking on Artificial Intelligence (AI) without a clear strategy. AI tools already in-house without inventory, board asking for a strategy, KRITIS and NIS2 pressure in the background. The audit delivers a written decision basis instead of workshop mood. Honest use-case list, data sovereignty per case, EU AI Act classification, plan. Phase 1 scoped, terms mandate-specific.

Regulatory Framework

Three threads.
All running hot in 2026.

Bitkom reports: close to ~57 % of German companies had no concrete AI Act plan as of mid-2025. At the same time, the EU AI Act, NIS2, and third-country transfer risks are on a collision course. Anyone without a written basis by the deadline is making decisions without facts — under fine pressure.

EUR 35 million EU AI Act high-risk — Deadline 2 August 2026

Art. 113 EU AI Act: high-risk systems under Annex III must be operated in compliance from 2 August 2026. Fine up to EUR 35 million or 7 % of global turnover. Prohibitions under Art. 5 and the AI literacy obligation under Art. 4 have been in force since 2 February 2025. DACH industry triggers for high-risk: HR scoring, B2B credit scoring, machine safety inspection, facility access biometrics.

Source: EU AI Act Art. 113 + Annex III (2024/1689/EU, in force 01.08.2024)
~29,500 NIS2 — German entities with supply-chain due diligence

NIS2 covers according to the BSI Situation Report 2024 ~29,500 German entities as "important" or "particularly important". Supply-chain due diligence explicitly includes cloud LLM providers: anyone using a third-party data processor must document their security measures. Board-level liability is personal. AI providers qualify as suppliers.

Source: BSI Situation Report 2024 · NIS2 Implementation Act (NISG 2.0)
CLOUD Act + Schrems II Third-country transfer risk remains unresolved

The US CLOUD Act (2018) reaches US-domiciled providers even for EU infrastructure. Microsoft, AWS, and Google Cloud are affected. Schrems II (CJEU 2020) struck down the Privacy Shield successor; the EU-US Data Privacy Framework (2023) is legally vulnerable — noyb complaint is active. Anyone relying on cloud frontier APIs needs transfer impact assessments per use case. Sovereignty is the only structurally safe answer.

Source: CJEU C-311/18 (Schrems II, 2020) · US CLOUD Act (2018) · noyb complaint EU-US DPF (2023)
Four Audit Pillars

One decision basis.
Four building blocks.

No two audits are identical — depth and emphasis depend on where you stand. These four building blocks define the structure; what goes into Phase 1 we settle in the first call.

01

Inventory + Shadow AI

Complete inventory: which AI tools are officially in use, which are running via personal accounts or browser extensions. Microsoft Work Trend Index 2024: ~75 % BYOAI among knowledge workers. Shadow AI is not a fringe phenomenon — it is the starting point of any honest inventory.

02

Use Case List + Annex III Filter

Structured use case capture with a high-risk filter per Annex III: HR scoring, credit scoring, safety inspection, biometrics. For each use case: data category, model type, egress path, high-risk classification yes/no. Documented facts, no room for interpretation.

03

Vendor Landscape Cloud vs. On-Prem

Assessment of current and planned providers: GDPR third-country transfer status, CLOUD Act exposure, NIS2 supply-chain due diligence. DACH sovereignty options: AD IT Systems, IONOS AI Model Hub, Hetzner GPU, Open Telekom Cloud, StackIT, OVHcloud, Scaleway. Without reseller bias — we sell no licenses.

04

Roadmap + Sovereignty Mapping

Prioritized action plan: which use cases require immediate action, where on-prem migration makes sense, where cloud with a DLP egress layer remains defensible. Written, board-ready, with clear next steps.

Audit in practice

Three patterns that create audit demand.

Three situations where companies request an audit — not because the board decided to, but because reality forces it.

  1. Pattern 01 · Shadow AI

    IT does not know which data is leaving the building.

    Employees use ChatGPT, Perplexity, Grammarly Business via personal accounts — with customer emails, internal reports, draft proposals. IT is out of the loop, compliance is out of the loop, the data protection officer too. This is not a failure of individuals — it is a structural information vacuum. The audit makes it visible without looking for culprits.

    Consequence
    Uncontrolled data egress through uninventoried channels
    Frame-Reset
    Complete inventory as starting point, then build governance
  2. Pattern 02 · Cloud Default Bias

    "We'll use Azure OpenAI" — without a transfer impact assessment.

    Cloud frontier APIs are assumed as the default because they are quickly available. Third-country transfer risk, CLOUD Act exposure, Annex III high-risk classification get checked only later — once the pilot is running and dependencies have formed. Sovereign DACH hosting providers (AD IT Systems, IONOS, Hetzner, Open Telekom Cloud, StackIT) are never included in the evaluation. The audit closes this gap systematically, before decisions are made.

    Consequence
    Compliance rework under time pressure after pilot start
    Frame-Reset
    Vendor landscape assessment before pilot start, neutral and complete
  3. Pattern 03 · Compliance Blackbox

    The board asks for a strategy. Nobody has a written answer.

    The AI Act deadline is approaching, NIS2 is in force, the CISO is asking for an overview — and there is none. No use case list, no high-risk classification, no vendor assessment. Strategic decisions are made without a factual basis, or they get deferred until the pressure is too great. The audit delivers the document that closes this gap.

    Consequence
    Strategy pause under compliance pressure with no solid foundation
    Frame-Reset
    Written decision basis with use case list and roadmap

An audit is not an end in itself. It is the only foundation on which sound AI decisions can be made under regulatory pressure.

Before you call

Five questions, five straight answers.

"What is the concrete output of the audit?"
A written document with a use case list, Annex III high-risk classification per use case, vendor landscape assessment cloud vs. on-prem, and prioritized next steps. Board-ready. No slide deck.
"We have no AI project yet. Do we still need an audit?"
Probably yes — because of shadow AI. ~75 % of knowledge workers use AI tools independently (Microsoft Work Trend Index 2024), often via personal accounts. The audit uncovers what is already happening and gives you the basis to manage it before the auditor asks.
"Do you advise us on which vendor to choose?"
Yes, but without reseller bias. We sell no licenses and receive no commissions. The vendor assessment is neutral — DACH sovereignty hosting providers (AD IT Systems, IONOS, Hetzner, Open Telekom Cloud, StackIT, OVHcloud, Scaleway) and cloud frontier APIs are evaluated against the same criteria.
"What does Annex III of the AI Act mean for us in practice?"
Annex III lists high-risk categories that are typical in DACH mid-market: HR scoring, B2B credit scoring, machine safety inspection, facility access biometrics. Anyone operating an AI system in these categories must demonstrate conformity assessment, technical documentation, registration, and audit logs from 2 August 2026. The audit clarifies which of your use cases are affected.
"How does Phase 1 work?"
Phase 1 is scoped: use case and shadow AI inventory, Annex III filter, initial vendor landscape sketch. Terms are mandate-specific. Extensions are decided jointly after Phase 1 — no lock-in, no retainer pressure.
Experience & contact

Deep platform expertise.

25 years in IT, 14 of them in B2B commerce. Architecture mandates with large enterprises, building and steering distributed expert teams, vendor-neutral project rescue. Focus areas: platform architecture, project rescue, team operations.

Chris Zepernick

Senior consultant · Hamburg

What we have learned

No plan is also a plan — just not a good one.

Close to ~57 % of German companies had no concrete AI Act plan as of mid-2025 (Bitkom). That is not a number for panic — it is a signal that the deadline of 2 August 2026 will be realistically tight for many. Those who do an inventory today have options. Those who wait make decisions under pressure. We deliver the foundation so you keep your options.

How we work

Ready for an honest inventory?

AI Act deadline 2 August 2026. A few minutes on the phone — we clarify whether and where an audit makes sense for you, without obligation.