AI implementation in a company does not start with purchasing a license. It starts with organizing processes, data, and responsibilities. If an organization wants to meaningfully shorten service handling time, automate documents, improve sales work, or make better use of team knowledge, it should first assess its technology, competency, and legal readiness.
The quickest answer is: How should you prepare your company for AI implementation?
A guide for companies that want to implement AI without chaos: processes, data, team, security, RODO, AI Act, ROI, and pilot.
Why is preparation for AI more important than choosing a tool?
AI is no longer an experiment reserved for the largest corporations. For companies operating in Poland, it is becoming a practical tool for reducing customer service time, automating documents, organizing company knowledge, accelerating reporting, and relieving teams from repetitive work.
The problem appears when a company starts by buying licenses instead of organizing processes, data, and responsibilities. The outcome is often predictable: high enthusiasm, limited results, and growing organizational risk.
PARP indicates that the readiness of Polish companies to use AI systematically is uneven, and less advanced organizations more often face competency and financial barriers. McKinsey, in turn, shows that companies that achieve value from AI combine activities across six areas: strategy, talent, operating model, technology, data, and adoption and scaling.
In practice, AI readiness means eight things at once: a sound business objective, a process suitable for improvement, data of sufficient quality for the model to work, people who understand AI limitations, a baseline technology architecture, security rules, a legal compliance assessment, and a way to measure return on investment.
How should you prepare your company for AI implementation?
Preparing a company for AI should be treated as an operational project, not only as a technology purchase. A good starting point is the NIST AI RMF approach, which structures work around risk management, trustworthiness, privacy, security, and human oversight.
For generative AI, NIST also identifies risks such as hallucinations, data privacy, information integrity, information security, intellectual property, and dependencies on the component supply chain. OWASP adds risks specific to LLM-based applications, including prompt injection, insecure handling of model output, data poisoning, supply chain vulnerabilities, and system overload.
The most important rule is simple: do not implement AI into an undocumented process. A model can speed up work, but if the data is chaotic, responsibility is unclear, and users do not know when an output requires human review, AI will only expose the existing disorder faster.
Technology, data, team, and processes
Choose a process where AI makes business sense
The best use cases have three characteristics: they are frequent, time-consuming, and based on repeatable information patterns. In Polish companies, this most often means document handling, answers to recurring questions, research and knowledge summarization, offer generation, ticket analysis, reporting, lead qualification, or support for sales, administration, HR, and accounting.
Check the data before connecting the model
If a company has knowledge scattered across emails, PDFs, shared drives, the CRM, and employees' heads, AI will not solve the problem by itself. First, you need to determine which sources are reliable, who owns them, how content is updated, and where the model can be connected safely.
Assign owners and accountability
Even the best pilot will stall if no one owns the outcome. You need a business sponsor, a process owner, a person responsible for the data, IT or security support, and end users who will test the solution in their daily work.
Do not start with full automation
The first stage should have a limited scope, clear KPIs, and a human-in-the-loop. AI can prepare a response, analysis, classification, or recommendation, but in business-critical processes, a person should approve the result until quality and security have been confirmed on production data.
Minimum standard for AI readiness
If a company wants to start responsibly, the minimum standard before a pilot looks like this: there is one specific process to improve, there is a process owner and KPI, the data comes from an established source, users know when to trust the model and when human verification is required, and simple security and data handling rules are in place.
This level of minimum viable governance usually produces a better result than a broad implementation without clear accountability boundaries. It works especially well in SMEs, where there is no need to create a large AI department, but there must be clear accountability for the process, data, and outcome.
| Area | What to check before starting | Minimum standard | How to measure the result |
|---|---|---|---|
| Technology | Can the current stack be integrated with AI without manually re-entering data? | Access to 1-2 source systems, a test environment, activity logging | task completion time, number of manual steps |
| Data | Is it clear which data is current, complete, and permitted for use? | data owner, single source of truth, basic data cleansing | answer relevance, number of errors, escalation rate |
| Team | Do users understand the model’s limitations and verification rules? | short role-based training, usage instructions, business owner | adoption, active users, time to independent work |
| Processes | Is the process documented and does it have a start and end point? | as-is process map, to-be description, defined exceptions | SLA reduction, less manual work, fewer mistakes |
| Security | Is it clear what data may be provided to the model and where the logs are stored? | data classification, prompting rules, access control, backup | incidents, policy violations, audit results |
| Legal compliance | Does the use case process personal data or could it affect individuals’ rights? | analysis of the legal basis, assessment of whether a DPIA is required, decision register | no non-compliance, complete documentation |
| ROI | Is it clear what should improve and how much it is worth? | 1 primary KPI and 2 supporting KPIs, baseline before implementation | hours saved, cost per transaction, conversion increase |
| Pilot | Is the scope small enough to draw conclusions quickly? | 6-12 weeks, one organizational unit, success and stop criteria | pilot result, decision: scale, improve, or close |
Security, GDPR, the AI Act, and risk control
At the security layer, you should assume that the model may be wrong, disclose overly broad knowledge, or be manipulated through user input. For this reason, AI applications in a company should have limited access to data, rules for masking or excluding sensitive data, operation logging, access control, prompt injection testing, and clear rules for when an AI output requires human approval.
Companies operating in Poland should account for at least three regulatory frameworks. First, the AI Act: the regulation entered into force on August 1, 2024; as of February 2, 2025, prohibitions on unacceptable practices and AI literacy provisions apply, while most provisions apply from August 2, 2026. Second, GDPR: if the project involves personal data, the legal basis, minimization, transparency, and security of processing must be assessed. Third, in some scenarios, a DPIA must be considered.
The Polish Data Protection Office (UODO) indicates that processing data to create and deploy high-risk AI systems may, with high probability, create a high risk to the rights or freedoms of natural persons, and therefore may require a data protection impact assessment. This means that prompt training is not enough. Rules, roles, a decision register, and evidence of controls are needed.
- do not enter personal data, trade secrets, or confidential documents into AI tools without a clear basis and policy
- limit the model’s permissions to the data it truly needs for the task
- record activity logs, but define retention and access to logs
- test prompt injection, incorrect answers, hallucinations, and integration vulnerabilities
- for decision-making processes, use human-in-the-loop and an escalation path
- adapt training to roles: users, administrators, and process owners each require different training
How do you calculate ROI from an AI implementation?
It is best to calculate ROI from the perspective of one process, not from a general claim that AI will increase productivity. In practice, we measure saved work hours, shorter response or handling time, fewer errors, higher conversion, shorter onboarding, or fewer escalations.
The most credible cases show results at the process level. Klarna measured customer service, Sandvik measured access to documentation and productivity, and Morgan Stanley measured adoption and access to advisor knowledge. The same model is worth applying in a smaller company: one process, a baseline before implementation, measurement after the pilot, and a decision on scaling.
| KPI type | What to measure | What it means for the business |
|---|---|---|
| Operational | average case handling time, number of manual steps, first response time | whether AI actually shortens the process |
| Quality | percentage of responses requiring correction, classification accuracy, number of escalations | whether the output is good enough for operational use |
| Financial | hours recovered per month, cost of handling a case, cost of errors | whether the implementation has a measurable return |
| Adoption | active users, number of uses, time to independent work | whether the team actually uses the solution |
| Risk | policy violations, use of sensitive data, security incidents | whether the solution operates within the accepted boundaries |
Estimate a simple automation payback.
This is an indicative model. A production assessment should also include error risk, customer response time, downtime and maintenance.
90-day AI pilot schedule
The best first pilot is small, measurable, and operationally manageable. It should have one sponsor, one team, one primary success metric, and clearly defined closure criteria. Many companies fail not because AI does not work, but because the pilot tries to fix data, change the process, train everyone, and implement five tools at once.
It is much more reasonable to start with one process in the category of documents, quotes, tickets, or internal knowledge, and only scale the solution to additional areas after the result is confirmed.
- Week 1-2
Audit of processes, data, tools, and legal constraints.
- Week 3-4
Selection of the use case, KPIs, owners, and success criteria.
- Week 5-6
Architecture, integrations, data access, and security rules.
- Week 7-9
Pilot build, knowledge base, prompts, escalation rules, and logging.
- Week 10-11
Usability testing, quality evaluation, team training, and fixes.
- Week 12
Pilot launch, ROI measurement, and a decision: scale, improve, or shut down.
Industry examples
Retail and e-commerce
Klarna launched an AI assistant for customer service. According to public information, in its first month the solution handled 2.3 million conversations, or about two-thirds of customer service chats, reduced repeat contacts by 25%, and shortened case resolution time from 11 minutes to less than 2 minutes. The takeaway for e-commerce is straightforward: AI is best started where the company has many repetitive questions and good access to data about products, returns, and order statuses.
Manufacturing
Sandvik built Manufacturing Copilot on Microsoft Azure OpenAI Service and Azure AI Search to make years of product documentation and service knowledge easier to access. Microsoft describes productivity improvement of up to 30% and cutting onboarding time for new salespeople in half. For manufacturing companies, the most cost-effective use cases often involve faster access to documentation and instructions, rather than impressive chatbots.
Finance and wealth management
Morgan Stanley started with a narrowly defined goal: faster information retrieval and knowledge summarization for financial advisors. OpenAI states that more than 98% of advisor teams use AI @ Morgan Stanley Assistant, and document access increased from 20% to 80%. The implementation approach is especially important here: pilot, evaluation, quality control, and only then scaling.
Insurance and the Polish market
In 2025, PZU announced a strategic collaboration with Google Cloud and OChK. In the first stage, AI tools for analyzing documents and customer messages were tested, while a secure landing zone base environment was built in Google Cloud in parallel. This is a good Polish example: before a company begins using AI broadly, it first builds the technology foundation and tests specific scenarios.
Tools and vendors
The table below does not identify one best tool for everyone. It shows how to match technology to the maturity stage and the type of problem: knowledge work, integration, automation, infrastructure, or local compliance requirements.
Prices are indicative and come from public vendor websites checked on May 28, 2026. Vendors often change pricing, currencies, promotions, and feature scope, so it is worth confirming them with the vendor or implementation partner before making a purchase decision.
| Tool | Type | Strongest use case | Distinguishing features | Estimated cost |
|---|---|---|---|---|
| ChatGPT Business | global | knowledge work, analysis, content creation, team assistants | shared workspace, GPTs, Projects, Apps, Company Knowledge, workspace data is not used for training | 20 USD/user/month annually or 25 USD/user/month monthly, minimum 2 users |
| Microsoft 365 Copilot | global | Word, Excel, Outlook, Teams, knowledge in the Microsoft ecosystem | integration with Microsoft 365, Copilot Chat, Microsoft adoption and security tools | local pricing depends on the plan and promotions; the Polish Microsoft site shows an offer with a promotional period until 06.30.2026 |
| Google Workspace with Gemini | global | Gmail, Docs, Drive, Meet, and teams' daily work | Gemini in Workspace apps, NotebookLM, Google Workspace security | Business Starter, Standard, and Plus according to the Polish Google Workspace price list |
| Claude Team | global | content editing, document analysis, teamwork | plan for teams of 5-150 people, standard and premium seat | 20 USD/user/month annually or 25 USD/user/month monthly for a standard seat |
| n8n | global / self-hosted | technical workflows, integrations, AI workflows, and automations with hosting control | unlimited users and workflows, self-hosting, Code node, queues, and many integrations | Starter 20 EUR/month annually, Pro 50 EUR/month, Business 667 EUR/month annually self-hosted |
| Make | global | fast no-code automation and SaaS application integration | 3000+ apps, visual workflow builder, AI apps, API | Core 9 USD/month, Pro 16 USD/month, Teams 29 USD/month with 10k credits |
| OChK Cloud for AI | local / Poland | companies that require a local cloud partner and control over data | one ecosystem, multiple models, shared API, emphasis on cyber resilience and compliance | not publicly specified |
| Synerise | local / Poland | retail, marketing, personalization, and real-time decisions | real-time behavioral signals, personalization, automation, and predictions at large scale | not publicly specified |
In practice, it is useful to divide the choice into three layers: tools for users, orchestration and automation, and infrastructure or an implementation partner.
How can SmartCodeIT help?
SmartCodeIT helps move from interest in AI to a concrete implementation process. We start with a readiness audit: we review processes, data, systems, risks, team skills, and possible KPI. Then we select the first use case that can be implemented as a pilot without overspending.
Depending on the needs, the project may lead to an AI agent based on company knowledge, document automation and OCR, CRM integration, a document panel, a dashboard, a workflow in Make or n8n, team training, or a dedicated web application. For companies in Gliwice, Katowice, and Silesia, this is a practical way to start with a small MVP and then develop the solution together with the organization.
The best first step is a discussion about the process, not the tool. Only after that is it worth deciding whether the company needs ChatGPT Business, Copilot, Gemini, n8n, Make, an AI agent, its own application, or just a well-defined procedure for working with AI.
FAQ
Does every company need an AI strategy before it starts taking action?
No. A small or medium-sized company usually does not need a full corporate strategy right away, but it does need a minimum foundation: a list of priority processes, one business owner, success criteria, and rules for working with data.
What is the best place to start with AI implementation in an SMB?
Start with a frequent, repeatable, and easy-to-measure process, such as documents, proposals, responses to inquiries, ticket classification, or work with company knowledge.
Do you need to hire ML specialists right away to implement AI?
Not always. Many first implementations are based on ready-made models, tools, and integrations. However, capabilities are needed in data analysis, tool selection, security, change management, and process design.
Do employees need to be trained in AI?
Yes. The AI Act requires measures to ensure an appropriate level of AI literacy. In practice, a company needs people who understand the model’s limitations, data handling rules, and the points where human verification is required.
Does every AI implementation require a DPIA?
Not every one. If the project involves personal data and may create a high risk to the rights or freedoms of natural persons, a DPIA is mandatory. For high-risk AI systems, you should assume that such an assessment may be needed.
How do you calculate ROI from an AI pilot?
The simplest approach is at the level of a single process: compare the before and after state in terms of handling time, number of errors, labor cost, number of escalations, onboarding time, or sales conversion.
Is it better to choose an off-the-shelf tool or a custom solution?
If the problem is typical and fits within the Microsoft, Google, or OpenAI ecosystem, it is worth starting with an off-the-shelf tool. If the company needs to work with its own data, multiple integrations, and a specific workflow, a better direction is an integration layer, an AI agent, or a custom solution.
How long should the first AI pilot take?
Most often, 6-12 weeks. This is usually enough to assess data quality, user adoption, and the real impact on KPIs without freezing the project for several months.
Is company data in AI tools used to train models?
It depends on the provider and the plan. OpenAI states that ChatGPT Business does not train on workspace data. For other tools, you must check the terms, privacy settings, DPA, and data processing policy each time.
Can SmartCodeIT prepare a company for AI implementation?
Yes. SmartCodeIT can conduct an AI readiness audit, identify the first use case, prepare a pilot, train the team, and implement automation, an AI agent, integrations, or a dedicated application.
Sources
- PARP: readiness of Polish companies for AI
- McKinsey: The State of AI 2025
- NIST: AI Risk Management Framework
- NIST: Generative AI Profile
- OWASP: Top 10 for LLM Applications
- European Commission: navigating the AI Act
- AI Act Service Desk: Article 4 AI literacy
- UODO: guidance on DPIA and AI
- OpenAI Help Center: ChatGPT Business
- Microsoft 365 Copilot pricing
- Google Workspace pricing
- Claude Team plan
- n8n pricing
- Make pricing
- OChK Cloud for AI
- Synerise Behavioral AI Infrastructure
- Klarna AI assistant announcement
- Microsoft Customer Stories: Sandvik Manufacturing Copilot
- OpenAI Customer Stories: Morgan Stanley
- PZU: collaboration with Google Cloud and OChK
Want to identify which process in your company should be improved with AI first? SmartCodeIT can audit your processes, data, and risks, then prepare a secure pilot with measurable ROI.
Schedule an AI readiness audit