AI needs clarity
Why most companies are stuck between uncontrolled growth and a ban
In recent months, the EU AI Act for high-risk systems has come into force. The conferences on the subject are over, the checklists have been ticked off. Nevertheless, one question remains unanswered in many companies – a question that isn’t addressed in any regulation: Who actually makes the decisions – the AI, or the people working with it?
Most organisations do not answer this question. They sidestep it in two ways: either AI use within the company proceeds unregulated behind the scenes, with everyone experimenting on their own; or it is restricted across the board because nobody wants to take responsibility for a nuanced set of rules. Both feel like a solution. In reality, both are simply a form of avoidance.
- Uncontrolled growth and outright bans are two sides of the same unanswered question: where should AI be allowed to act autonomously, where should it merely make suggestions, and where must a human make the decision?
- A simple four-zone model brings this clarification to life using examples rather than an abstract guideline.
- Clarity is not a document, but a state of practice: it is evident from whether any member of staff can explain why a particular process falls within a specific zone.
Two extremes, one blind spot
Two examples illustrate just how differently this avoidance can manifest itself. In one company, virtually every team uses AI tools at their own discretion – for drafting texts, analysing data, and in some cases even for pre-screening job applications or customer enquiries. Nobody has banned it, but nobody has regulated it either. Management usually only finds out about the extent of its use when something goes wrong.
In the other company, it’s the other way round: following a data protection scare, all generative AI tools were blocked by order – even for harmless tasks such as summarising internal minutes. Since then, staff have been resorting to private accounts because the drop in productivity would otherwise be too great. The regulation has given rise to a new form of ‘shadow use’, only more invisible than before.
Neither company has answered the same question: where is AI permitted to act autonomously, where is it only allowed to make suggestions, and where must a human make the decision? One has ignored the question; the other has dismissed it with a blanket ‘no’. Neither has actually resolved it.
Both situations appear stable at the moment – until they are no longer so. In the first company, a single incident is enough to turn tacit tolerance into a frantic crisis response: a suspicion of bias in an automated pre-selection process, a customer complaint about AI-generated misinformation, or a works council enquiry that nobody can answer because nobody has the full picture. In the second company, the risk continues to grow unseen: private accounts are not subject to any of the controls that the ban was actually intended to put in place, and sensitive company data ends up in tools completely beyond the reach of the IT department.
What is missing in both cases is not another rule, but an answer that is actually known throughout the organisation: who makes the decision – the AI alone, a human with its support, or a human entirely without it? This is precisely what is meant by clarity: not an additional guideline, but a practical answer to this question that is understood by everyone.
Why it isn’t down to a lack of rules
The obvious instinct is to call for more rules: an AI policy, terms of use, a whitelist of approved tools. Such documents aren’t wrong, but they rarely solve the actual problem. For the problem is usually not a lack of rules, but a lack of moderation: No one is clearly responsible for clarifying the issue of autonomy and responsibility in consultation with the specialist departments, rather than over their heads.
A guideline drawn up by the compliance team and distributed via a circular email provides a formal answer to the question. Yet it is rarely put into practice because the people who are supposed to implement it were not involved in its creation and do not recognise their own practical realities within it. The result is both adherence to the rule and its circumvention – side by side, not intertwined.
The difference often only becomes apparent in a crisis. A guideline may stipulate that ‘AI may only be used in a supporting role for decisions involving personal data’; a statement with which hardly anyone would disagree. What is missing in practice is the translation of this statement into the specific process: Does the automated pre-sorting of job applications already count as ‘supportive’, or is it already a preliminary decision? A guideline alone cannot perform precisely this task of translation. It requires the specialist departments that are actually responsible for the process, and someone to facilitate clarification, rather than imposing it or sidestepping it.
Four zones, a straightforward map for clarity
A model that has proven its worth in practice distinguishes between four zones – not based on technology, but on the scope of the decision:
- Zone A – Limited scope; AI may act independently.
- Zone B – AI makes a proposal; a human reviews it before it is implemented.
- Zone C – A human makes the decision; AI merely provides information or a draft.
- Zone D – Genuine conflict of values; AI must not be involved in the decision-making here.
Figure: Four zones categorised according to the scope of a decision
- When AI suggests and coordinates interview appointments, this falls within Zone A – low impact, clearly reversible.
- When it pre-sorts incoming applications according to defined criteria, this falls within Zone B – a suggestion that a recruiter checks before sending out an invitation.
- When it comes to drafting a rejection letter, AI can provide a draft, but the decision on who receives a rejection remains in Zone C with a human.
- And when it comes to the actual hiring decision, where diversity targets, team dynamics and other considerations not purely driven by data play a role, this is Zone D – here, AI must neither make a preliminary decision nor set the parameters.
The value of the model lies not in the categorisation alone, but in the fact that it explicitly raises the question in the first place. Most conflicts in practice arise not because someone wanted to use AI in Zone D, but because it was never made clear that this zone exists.
What happens when an organisation fails to make this distinction becomes most evident when Zone C and Zone D are conflated. A company that wanted to use AI purely to prepare for recruitment decisions found itself struggling to explain its position when an applicant asked about the criteria for their rejection – no one could say definitively how much of the decision was actually made by humans and how much was already determined by the automated ranking. Not because anyone deliberately wanted to abdicate responsibility, but because the line between ‘providing information’ (Zone C) and ‘making the actual value judgement’ (Zone D) was never explicitly drawn.
The model can be applied to other areas. In customer service, automated responses to simple standard enquiries might fall within Zone A; drafting a goodwill policy in response to a complaint within Zone B; a refund above a certain threshold within Zone C; and a decision concerning a long-standing customer that goes beyond the purely commercial transaction within Zone D. The specific boundaries vary from organisation to organisation. What matters is not the exact classification, but that it is made consciously in the first place and that it remains transparent to all those involved, not just the person who devised it.
Clarification is a process, not a decision imposed from above
Two approaches to implementing this model regularly fail. The first: senior management centrally determines the zone allocation and announces it. The result is formally complete, but there is a lack of acceptance, as the specialist departments perceive the allocation as impractical and quietly circumvent it. The second: Clarification does not take place at all because responsibility for it is not clearly assigned to anyone – neither IT, nor HR, nor Compliance feels solely responsible, and so the situation remains one of individual decisions without a common framework.
What tends to work better in practice is a facilitating role: for a limited period, with a clearly defined end date. This role develops the zone allocation in collaboration with the departments concerned – in a framework workshop rather than via a circular email – oversees an initial operational test cycle with fixed reviews, and then hands over to a designated internal individual or a small committee as soon as the organisation can sustain the structure itself.
The difference compared to a permanent governance role is that this role helps to establish that position; it does not replace it in the long term. And responsibility for AI decisions involving personal data always remains with a designated individual within the organisation itself – never with the facilitating role.
The impetus for this does not necessarily have to come from senior management. It is often project or team leaders who first recognise the need, as they directly experience the daily ‘shadow’ use of AI or the friction caused by a blanket ban. Anyone in this position cannot impose a resolution themselves, but they can certainly provide the impetus for it: by presenting a concrete observation rather than an abstract concern, and by using the four-zone model as a basis for discussion, which is immediately understandable even to non-specialists.
The test case for genuine clarity
Whether an organisation has truly reached this stage can be checked with a simple test: ask a randomly selected member of staff – not the manager who facilitated the workshop – why a particular process falls within her zone. If she can explain it, the classification is being put into practice. If she cannot, there is probably a document, but no clarity.
A second test complements the first: a simulated borderline case, a tabletop exercise involving a decision that does not fit clearly into any one zone. If it turns out that those involved know who to turn to in this case, the structure will hold up even when reality is more complicated than the model.
Both tests assess the same thing: not whether a document exists, but whether the clarification has become part of day-to-day practice. A zone allocation that exists only in a presentation rarely stands up to the first real borderline case; one that has been developed collaboratively and is subsequently maintained through reviews usually does.
The question will follow you either way
The process of clarifying where AI is permitted to make decisions and where it is not takes place in every organisation – whether guided or unguided, whether deliberately or as a by-product of chance and habit. The only open question is whether someone actively shapes this process before the first serious incident does it for the organisation.
Uncontrolled growth and outright bans are both more convenient than this clarification. At the same time, both are more costly once you look beyond the next quarter.
What matters in the end is not whether your organisation has an opinion on AI – practically every organisation does. It is whether it has clarity: an answer to the question of who makes decisions, which everyone involved knows and can explain, not just those who originally formulated it.
Notes:
Guido Bosbach supports organisations on their journey towards clarity in dealing with AI. He would be happy to discuss with you how to clarify AI responsibility within your company. Simply contact him via his website or message him on LinkedIn.
Also highly recommended is his German-language workLIFE Stories blog, where he regularly shares experiences from the business world, ideas and insights.
Would you like to support Guido Bosbach and discuss clarity in the use of AI and the four-zone model presented here? Then please share this post on social media or within your organisation.

Guido Bosbach
Guido Bosbach advises management boards and leadership teams on how to gain clarity regarding responsibility, decision-making processes and values within their organisations – before these issues escalate into unresolved conflicts. He supports companies from the initial assessment right through to the establishment of a regular review process, currently with a particular focus on how organisations can clarify responsibility for AI decisions without permanently outsourcing them.
In the t2informatik Blog, we publish articles for people in organisations. For these people, we develop and modernise software. Pragmatic. ✔️ Personal. ✔️ Professional. ✔️ Click here to find out more.
