How we use AI
wegewerk's AI guidelines
1) Purpose, Scope, Definitions
- Our mission is to support organisations dedicated to the public good in achieving their objectives. By utilising AI, our clients could achieve greater impact with the same level of resources. This helps them to achieve their objectives.
- In doing so, we advise our clients not only on the use of AI in their external communications, but also on its internal application for their work and knowledge management processes.
- Our principles apply both to purchased solutions and to AI applications developed by us.
- Our principles also apply to our internal work and knowledge management processes, some of which form the basis for our advice on the use of AI by our clients.
- This policy does not apply to high-risk AI systems as defined in Annex III of EU Regulation 2024/1689 (EU AI Act); these require appropriate adaptation.
- We distinguish between the use of AI by humans (augmented intelligence) and by agents (automated intelligence). The decisive factor here is not whether quality control (‘human-in-the-loop’) takes place, but who controls the process.
2) Transparency and disclosure in information processing
By labelling the use of AI, we make it clear whether the content and creative output is attributable to a human or a machine. In doing so, we follow Section 2 of the EU’s proposed Code of Practice on the labelling of AI-generated content. Accordingly:
- We label information generated entirely by AI with an ‘AI GENERATED’ notice or icon in accordance with Annex 1 of the CoP.
- We label information partially generated by AI with an ‘AI MODIFIED’ notice or icon in accordance with Annex 1 of the CoP.
- This labelling may be omitted if AI-generated texts have been reviewed by humans prior to publication in accordance with the otherwise applicable quality standards. In such cases, the name, role and email address of the reviewer must be documented where technically feasible; furthermore, the review process itself must be documented and effectively implemented.
In addition: - In line with our guiding principle ‘We want to be understood’, we make use of the option to translate the notice wherever possible.
- Linguistic revision or blending with human-generated content does not exempt us from the labelling requirement; the decisive factor is the review of all AI-generated information.
- Where unverified translations are used, a notice may be provided in a central location (e.g. in the legal notice) provided that they have passed an objective test in accordance with Section 3.
When used as chatbots:
- When people communicate directly with AI, they must be informed of this in an appropriate manner before the interaction begins.
- Conversation partners must be informed about the processing of their data by AI systems. A link must be provided to the privacy policy, which must be supplemented with information on the scope, purpose and legal basis of the processing by AI, as well as, where applicable, on rights (e.g. the right to an explanation and the right to access data), particularly when external services are used.
- As soon as personal data is processed – which is generally to be expected in chat systems – we recommend using European LLM providers or LLMs hosted by us or by the client.
When used for image generation:
- Where AI-generated images or voices of real people, or images or sounds of real objects, are used, the product is considered to be partially AI-generated information.
- If real image material has merely been modified by AI in a way that would also be possible through conventional, non-AI-assisted image editing with reasonable effort, labelling is not required.
- If AI has been used to carry out routine tasks (e.g. cropping) or for inspiration, labelling is not required, provided that the creation and the final result remain attributable to humans.
3) Accuracy and supervision
- The verification of information we have researched and which is intended for the public is carried out with journalistic rigour (plausibility, credibility of sources, cross-checking). This verification cannot be carried out by AI or supported by AI.
- Where we utilise Automated Intelligence, we first ensure, through tests objectified by several people, that the quality of the AI results does not exceed the error rate of a suitably qualified person typically employed for the task.
In objectified tests, several people capable of assessing the process use a representative sample to distinguish between good results, results with minor errors and results with significant errors. Significantly flawed results preclude the use of Automated Intelligence. - Through the appropriate selection of representative samples, we ensure that AI results do not contribute to the formation or reinforcement of stereotypes (e.g. regarding skin colour, gender, language and age).
- Where we allow third parties to use our AI systems, we use prompts and tests, to an extent appropriate to the nature of the risk, to ensure that AI systems are used only for their intended purpose and cannot be misused.
- The quality of results is monitored at appropriate intervals, as well as whenever the LLM or LLM version is changed.
- Approval for the use of automated intelligence in routine operations is granted following the successful completion of an objective test by senior management.
- In the case of AI-supported processing of special categories of personal data in accordance with Article 9 of the GDPR, the processing of personal data on a large scale, the systematic evaluation of personal characteristics, and in the event of unforeseeable risks arising from direct contact with innovative technologies (e.g. incorrect recommendations or discrimination), we advise our clients of the need for a data protection impact assessment (DPIA).
4) Ethical considerations
Social aspects:
- We make targeted use of AI to automate repetitive and time-consuming routine tasks in day-to-day work. In doing so, we free up capacity for conceptual, creative and strategic work – where human expertise offers the greatest added value.
- In profit-oriented companies, AI can reduce labour costs. As long as this business incentive is not counterbalanced by an economic strategy that replaces gainful employment as the basis of purchasing power and tax revenue, the use of AI to reduce labour costs must be regarded as unsustainable and contradicts our consulting approach.
- We therefore prioritise the automation of routine processes that, without AI, would not take place at all, or would only occur occasionally or superficially, in order to free up time for more effective activities.
- We reject the use of AI to monitor human activity.
- When selecting service providers, we actively take social aspects into account, such as the working conditions of data workers and the transparency of the relevant supply chains.
- In addition, when selecting service providers, we pay attention to ethical aspects such as the disclosure of training data sources, the prevention of non-defensive military uses or uses that violate human dignity, etc.
Economic and environmental aspects:
- The energy consumption of LLMs increases linearly with model size. We therefore test for a Pareto-optimal balance between model size and output quality for each specific use case.
- AI already consumes a large proportion of its energy during training. We therefore favour – where possible – models with a smaller environmental footprint.
- The AI models we provide utilise resource-efficient environments in energy-efficient data centres powered by electricity from renewable sources.
- For third-party AI models, we give preference to service providers with an environmentally sustainable operating model.
Digital sovereignty
- For data protection reasons and due to the geopolitical situation, we avoid providers outside the scope of the EU AI Act.
- Given the lock-in and buy-out risks associated with proprietary solutions, only the use of open source guarantees long-term sovereignty.
5) Internal use
- AI applications, including those classified as augmented intelligence, may only be used following basic training that covers the functioning, capabilities, limitations and risks associated with AI use.
- To ensure compliance with the requirements of this policy, only selected AI services are permitted on a permanent basis. These can be found here: www.wegewerk.com/service/ai-partner.
- Any other services must be assessed in accordance with this policy before use. Work accounts may be created for this purpose for testing purposes.
- For general-purpose AI applications, we create individual company accounts anonymously using the employee code or group accounts. Company accounts must not be used for private purposes. Conversely, private accounts must not be used to process our customers’ information.
6) Data protection and the protection of personal data
- The AI systems we use are granted access to personal data only where necessary and lawful.
- Where we train systems, training data must be documented.
- Where we process personal data using AI, this is carried out exclusively by European providers, provided that this prevents any transfer of data to parties outside the EU legal framework.
- Where we process special categories of personal data using AI, this is carried out exclusively using open-rate models on servers operated by us or by the customer.
7) Prohibitions
- The use of AI applications without a valid legal basis (e.g. consent, contract, legitimate interest and lawful processing of personal data) is prohibited.
- The provision of medical or legal advice, biometric categorisation, emotion recognition in the workplace, the manipulation of vulnerable individuals or the scraping of personal data are prohibited.
- The use of AI for far-reaching decisions (e.g. recruitment, allocation of funding) requires appropriate human oversight; use without human oversight is prohibited.
- The generation of media content that authentically depicts real people (deepfakes) is generally prohibited due to the problem of blurring the lines between fiction and reality. Any exceptional use must be well-justified (e.g. for visualising future scenarios), must be labelled in accordance with the Code of Practice, and must unambiguously uphold the standard of truthfulness set out in the Code of Conduct of the German Association for Political Consultants.
8) Accountability and Compliance
- The Data Protection Coordinator is responsible for assessing the compliance of our AI applications and for updating processing registers. In cases of doubt, the Data Protection Coordinator consults our Data Protection Officer on data protection matters and the management team on ethical issues.
- Breaches of the AI Policy may result in disciplinary measures ranging from compulsory training and written warnings to dismissal on grounds of conduct.
9) Review and updating
- Management is responsible for the ongoing development and training of staff in the application of these guidelines.
- The AI Policy is reviewed quarterly at Security Committee meetings and updated as necessary to reflect technical or regulatory changes (in particular with regard to the AI Act and the EU’s GDPR).
10) Feedback and Improvement
- AI is constantly evolving. To ensure the quality of further development, it is essential to document the current status. We support this by carefully documenting our own tests in accordance with Section 3, as well as customer feedback from acceptance processes, within the project documentation. Responsibility for this lies with project management.
- Test reports are not trade secrets. Unless a re-evaluation by us is requested, we make these available to customers on request when changing or updating the AI solution, in order to facilitate a re-evaluation.
SOURCES:
- https://www.isaca.org/resources/white-papers/2024/understanding-the-eu-ai-act
- https://artificialintelligenceact.eu/high-level-summary/
- https://www.europarl.europa.eu/topics/en/article/20230601STO93804/eu-ai-act-first-regulation-on-artificial-intelligence
- https://www.gtlaw.com/en/insights/2025/7/eu-ai-act-key-compliance-considerations-ahead-of-august-2025
- https://www.degepol.de/aktuelles/degepol-empfehlungen-ergnzen-verhaltenskodex-positionierung-zur-nutzung-von-ki-in-der-politischen-kommunikation (German only)