In this guide
- What is generative AI?
- Which use cases can deliver verifiable value?
- How should you choose a use case and solution?
- Which risks should be tested before deployment?
- How should generative AI data be governed?
- What human review should remain?
- A 30-day generative AI pilot roadmap
- How can you measure a pilot without inventing ROI?
- Generative AI frequently asked questions
- Official sources
In brief
Generative AI creates new content from an instruction and the context available to it. In business, it is most useful when a task is repeated, language-heavy and verifiable by a qualified person. The right starting point is therefore not the most popular tool, but a bounded problem, an approved data source, a human owner and a measured baseline.
Key takeaways
- 01Start with a frequent, reversible task whose output is easy to check.
- 02Compare at least two options on the same representative cases before choosing a vendor.
- 03Share only data that is necessary, authorised and compatible with the selected product terms.
- 04Keep human review proportionate to the impact of an error.
- 05Measure the pilot against an observed baseline and claim no gain before the evidence exists.
What is generative AI?
Generative AI describes systems that can produce text, images, audio, video or code from instructions and examples. A language model, for example, generates a response by estimating plausible sequences of words. It does not automatically consult a guaranteed source of truth: a fluent answer may still be inaccurate, incomplete or out of context.
In business, the model becomes useful when it sits inside a process: a person defines the task, approved data provides context, the system proposes an output, and a rule or accountable reviewer checks it before use. That chain matters more than the model name.
It also helps to distinguish three levels. An assistant supports a person in a conversation. An embedded feature triggers generation inside business software. A workflow connects several steps, sources and controls. As autonomy grows, access controls, testing, logs and escalation paths become more important.
CNIL: Using generative AI in small and medium-sized businesses · FPS Economy — Belgium: Artificial intelligence and SMEs
Which use cases can deliver verifiable value?
Good first use cases transform existing content without making a decision on someone’s behalf: summarising, classifying, extracting, rewriting or preparing a first draft. They make it possible to compare the process clearly with and without AI.
| Function | Pilot use case | Required control |
|---|---|---|
| Customer support | Draft a reply from an approved knowledge base | An agent checks facts, tone and escalation before sending |
| Sales | Summarise call notes and propose next actions | The salesperson confirms commitments and customer data |
| Marketing | Turn an approved brief into message variants | The brand owner checks claims, rights and the published version |
| Operations | Extract fields from documents or draft a procedure | Exceptions and uncertain fields go to human review |
| Internal knowledge | Search and summarise authorised documents | The answer cites the documents used and flags missing information |
| Software development | Explain, document or propose a code test | Code review, testing and security analysis precede production use |
CNIL: Using generative AI in small and medium-sized businesses · France Num and CNIL: AI use cases for small and medium-sized businesses · FPS Economy — Belgium: Artificial intelligence and SMEs
How should you choose a use case and solution?
Evaluate the process before the product. An impressive answer to a generic demo question proves neither quality on your documents, cost at scale nor fit with your obligations.
- 01
1. Define the problem — Describe the user, trigger, input, expected output and the decision that follows. If success cannot be observed, the use case is still too vague.
- 02
2. Check controllability — Prefer an output a subject-matter expert can correct quickly, with an accessible source of truth and a manual fallback.
- 03
3. Classify the data — Identify personal, confidential, strategic and sector-regulated data before any test.
- 04
4. Compare solutions — Run the same cases through several products and examine quality, hosting, retention, data reuse, admin access, integrations, cost and portability.
- 05
5. Define human review — Name the person who accepts, corrects or rejects each output and specify which cases must be escalated.
- 06
6. Set the decision rule — Before the pilot, document the thresholds that will lead you to expand, change or stop the use case. The decision should not rely on impressions alone.
CNIL: Using generative AI in small and medium-sized businesses · CNIL: Questions and answers on using generative AI systems · OpenAI: Business data privacy, security and compliance
Which risks should be tested before deployment?
- Accuracy — The system may invent a fact, source or relationship. Test fidelity to approved documents and require verification for every material claim.
- Confidentiality — A prompt may contain personal data, trade secrets or client information. Minimise inputs and verify the technical and contractual terms of the selected product.
- Bias and unfair treatment — Outputs may reproduce bias in data or instructions. Do not use an unchecked output to assess a person or determine their rights or access.
- Intellectual property — An output may resemble an existing work or contain material with uncertain rights. Check sources, licences and intended uses before publication.
- Security — Malicious documents or instructions may redirect a connected system. Apply least privilege, isolate tests and block irreversible actions without approval.
- Dependency — A vendor’s price, model or terms can change. Preserve procedures, exportable data and a way to operate without AI.
CNIL: Questions and answers on using generative AI systems · CNIL: Using generative AI in small and medium-sized businesses · EUR-Lex: Regulation (EU) 2024/1689 on artificial intelligence
How should generative AI data be governed?
A business product may provide useful controls, but it does not make a use case automatically compliant. OpenAI, for example, states that it does not use inputs and outputs from its business products and API to train its models by default. That vendor policy still needs to be checked against the exact plan, features, region, retention settings and subprocessors selected.
France’s CNIL recommends defining allowed and prohibited uses, submitting only information the user is authorised to share, and reviewing outputs critically. In Belgium, the FPS Economy explains that a company using an AI system in its activities may be a deployer under the AI Act. The Belgian Data Protection Authority also highlights the interaction between AI systems and data-protection duties.
These points are operational guidance, not legal, security or sector-specific advice. If a use case affects people, sensitive data or a high-impact decision, involve the appropriate specialists before the pilot.
| Question | Evidence to obtain before the pilot |
|---|---|
| What data enters the system? | Inventory, classification, purpose and minimisation rule |
| Where does it go and how long is it retained? | Processing documentation, region, retention and deletion settings |
| Is it reused to train a model? | Terms for the exact product and verified administrator settings |
| Who can view or export interactions? | Roles, authentication, logs and offboarding procedure |
| Which systems can the AI call? | Connector list, minimum permissions and approval-gated actions |
| How can you leave the vendor? | Export, deletion, manual continuity and an internal process owner |
CNIL: Questions and answers on using generative AI systems · FPS Economy — Belgium: Using AI within your business · Belgian Data Protection Authority: Information brochure on artificial intelligence systems and the GDPR · OpenAI: Business data privacy, security and compliance
What human review should remain?
Human oversight is not a ceremonial approval step. The named reviewer must understand the task, have access to source material, be able to challenge the output and have enough time to intervene.
- Before generation — Approve the purpose, permitted data, instructions and boundaries of use.
- During the process — Expose sources, useful uncertainty signals and exceptions that need a human decision.
- Before action — Check facts, tone, rights, amounts and any potential effect on a person or customer.
- After use — Retain corrections, incidents and rejected outputs so the process improves without hiding failures.
CNIL: Using generative AI in small and medium-sized businesses · EUR-Lex: Regulation (EU) 2024/1689 on artificial intelligence
A 30-day generative AI pilot roadmap
- 01
Days 1–5 — Frame — Select one task, name its owner, measure the current process, inventory data and document prohibited uses.
- 02
Days 6–10 — Design — Build a representative test set and define the evaluation rubric, human review, permissions and incident procedure.
- 03
Days 11–15 — Compare — Test at least two configurations on the same cases. Keep every output, including failures, and choose using the criteria set in advance.
- 04
Days 16–24 — Pilot — Open the workflow to a small trained group within a limited, reversible scope. Log corrections, escalations, costs and incidents.
- 05
Days 25–28 — Evaluate — Compare results with the baseline, segment errors by type and interview users without replacing measurements with satisfaction alone.
- 06
Days 29–30 — Decide — Expand, modify or stop according to the pre-agreed thresholds. Record the decision, remaining limits, owner and next review date.
CNIL: Using generative AI in small and medium-sized businesses · CNIL: Questions and answers on using generative AI systems · EUR-Lex: Regulation (EU) 2024/1689 on artificial intelligence
How can you measure a pilot without inventing ROI?
First measure the current process on a comparable sample. The pilot should use the same definitions, unit of work and explicitly dated period. Do not turn a handful of successful examples into a general productivity percentage.
| Dimension | Measurable indicator | Method |
|---|---|---|
| Quality | Share of outputs accepted without major correction | Score a defined sample with a stable rubric and qualified reviewer |
| Accuracy | Share of claims confirmed by approved sources | Check facts and count errors, omissions and missing citations separately |
| Time | Median time per completed and approved unit | Include preparation, generation, correction and escalation |
| Cost | Full cost per approved unit | Include licences, integration, operations, human review and error handling |
| Risk | Incidents and near misses by type | Log data exposure, incorrect actions, bias and policy violations |
| Adoption | Share of trained users completing the workflow correctly | Observe real use and abandonment; do not equate a login with delivered value |
CNIL: Questions and answers on using generative AI systems · EUR-Lex: Regulation (EU) 2024/1689 on artificial intelligence
Generative AI frequently asked questions
What is the difference between AI and generative AI?
Artificial intelligence covers systems that produce predictions, recommendations, decisions or content. Generative AI is the family focused on creating new content such as text, images, audio, video or code.
What is the best first business use case?
A frequent, bounded and reversible task with an output that is easy to verify: summarising an authorised document, drafting a response or extracting fields. The best choice depends on your process and should be confirmed against a measured baseline.
Can personal data be sent to a generative AI system?
Not by default. Identify the purpose, strictly necessary data, applicable basis, vendor terms, retention and access. For consumer services, CNIL advises never sharing confidential or personal information. Seek qualified advice when the processing is sensitive or uncertain.
Does a business product guarantee GDPR compliance?
No. Contractual and technical safeguards may help, but the organisation remains responsible for its use, data, access and processes. Compliance depends on the actual processing, not only on the product purchased.
Should every generated answer be checked?
The level of review should follow the risk. Public, contractual or financial output—or anything that may affect a person—needs stronger control. Even an internal draft should have its facts and sources checked before reuse.
How should generative AI ROI be calculated?
First measure the time, cost, quality and incidents in the current process. Then compare full cost and approved units during the pilot. Do not treat theoretical savings or generation time alone as return on investment.
Is this guide legal advice?
No. It provides a general operational framework. Obligations vary by organisational role, system, data, sector and impact. Have sensitive situations reviewed by the appropriate internal owners or qualified advisers.
Official sources
- 01Regulation (EU) 2024/1689 on artificial intelligence — EUR-Lex
- 02Using generative AI in small and medium-sized businesses — CNIL
- 03AI use cases for small and medium-sized businesses — France Num and CNIL
- 04Questions and answers on using generative AI systems — CNIL
- 05Artificial intelligence and SMEs — FPS Economy — Belgium
- 06Using AI within your business — FPS Economy — Belgium
- 07Information brochure on artificial intelligence systems and the GDPR — Belgian Data Protection Authority
- 08Business data privacy, security and compliance — OpenAI
Read next
Turn an isolated test into a controlled AI process
Devauras helps you frame the use case, connect the right data, integrate human controls and build measurable AI automation.
Explore AI automation


