Skip to content
ORTHODROMECONSULTING
The guide

AI in a small or mid-sized company: where to start

You do not start with a tool. You start with a task that is repetitive, written down, measurable and not vital: something someone does every week, following a known rule, where a mistake can be caught. The first project is not there to transform the company. It is there to teach you — about your data, your habits, your tolerance for risk. What it teaches is worth more than what it automates.

Updated 04 August 2026

This resource provides general information, accurate as of the date shown. It does not constitute legal advice and does not replace analysis by a qualified professional in light of your situation.

How do you recognise a good first use case?

Five criteria, all of them checkable without technical expertise.

Frequency: the task comes round every week, not twice a year. Time spent: someone can say how many hours it costs. The rule: there is a way of doing it, written down or dictatable in ten minutes. Tolerance for error: a wrong answer is spotted, corrected, and commits neither safety nor the company’s signature. The data: what is needed to do the work already exists, in a usable form.

A case that ticks all five is rarely spectacular. Incoming requests, meeting notes, quotation drafting, searching internal documents: that is where it starts.

One missing criterion is not disqualifying. Three are.

What should you check before starting?

Four questions, before the first euro is spent. Who decides? A project without a named owner stops at the first trade-off. You need someone who settles matters, and a real user who will say whether it helps.

Which data is involved? List it. Personal data, customer data, information covered by a contract: the regime differs, and it is settled beforehand.

Who may access it — and where is it allowed to go? The tool must not open to anyone what their current access rights refuse them, nor send outside the company what has to stay in it.

What happens if the output is wrong? Who sees it, who corrects it, what it costs. If nobody can answer, the use case is the wrong one.

What sequence actually works?

Four steps. Frame it: one page — the task in scope, who does it today, what counts as a good result, what is out of scope. If that page will not write itself, the project is not ripe.

Try small. A limited version, on a real piece of work, with two or three willing users. Not a demo: a trial in real conditions.

Evaluate on real cases. Take files already handled, where you know the right answer, and compare. It is tedious; it is the only proof worth having.

Decide. Extend, adjust, or stop. The right to stop is part of the method: a trial that concludes “no” has done its job. That is the whole point of starting small.

Which mistakes come up most often?

Four, and they look much the same from one company to the next. Starting with the most visible case rather than the simplest: the topic everyone talks about is usually the most tangled — several departments, scattered data, high exposure. Keep it for the second project.

Confusing a demo with going live. A convincing mock-up says nothing about the work left: access rights, edge cases, error recovery, training.

Planning nobody for upkeep. A tool lives: documents change, rules evolve, models too. With no named owner, it degrades quietly.

Believing you must “train an AI on our data”. Usually not: the system consults your documents at question time, learning nothing from them. Simpler, faster, far easier to correct.

Which rules do you need to know?

Two texts, and they ask for different things.

The GDPR, as soon as personal data is involved — customers, employees, applicants. Legal basis, informing people, retention periods: the usual rules apply, and France’s data protection authority, the CNIL, publishes practical guidance dedicated to AI. An impact assessment becomes mandatory in certain cases, notably where there is profiling or automated decision-making.

The EU AI Act, in application since 2 August 2026, but in stages: a regulation adopted in July 2026 pushed the high-risk obligations back to 2 December 2027, and to 2 August 2028 for AI built into already-regulated products. Two points come sooner. AI literacy: since February 2025 you have to take measures so your teams learn about the tools they use — an obligation of means, not a level you must guarantee. Informing people: a system designed to talk with someone must let them know they are dealing with an AI, unless that is obvious from the context; the duty falls on whoever builds the tool.

Neither text forbids you to start. They require you to know what you are doing.

Do you need an outside partner, and what should you ask?

A first trial on off-the-shelf tools is often run in-house, provided someone is genuinely given the time. As soon as you have to connect your systems, handle access rights or keep the tool alive over time, outside help earns its place.

What you ask of a partner comes down to little: that they tell you where your data goes and under what terms; that they document what they build, so someone else can take it over; that they accept a success criterion written in advance; that they tell you when a case is not worth doing.

Look too at what already exists: France’s Directorate General for Enterprise runs a national plan to spread AI use, with part-funded diagnostics and support schemes open to smaller companies that meet the criteria.

When is it better not to start yet?

There are moments when the honest answer is “not yet”. When nobody has the time: an AI project consumes hours from the business side, not only from an IT person. Without those hours, the tool gets built on guesswork.

When the process is not settled. If the way of working changes every month, or nobody can say what a good result looks like, you will get faster disorder.

When the knowledge is written nowhere. What exists only in two people’s heads cannot be tooled; it has to be written down first.

When the real problem is elsewhere. Many topics presented as AI topics are solved by a form field, a clearer rule or one fewer meeting. We say so when that is the case.

Frequently asked questions

Do we need “clean” data before starting?
Not perfect data: legible data. What the chosen case needs must exist, be accessible, and you must know which version is authoritative. A large clean-up beforehand is almost never necessary for a first project.
How long does a first project take?
It depends on the case and on how available your teams are. The useful marker is not duration but format: a scope narrow enough to be evaluated on real cases, then extended or stopped.
Does our data end up with the AI vendor?
It depends on the solution and the contract. Ask before choosing, not after: data location, use for training, reversibility. Options hosted in Europe, or on your own infrastructure, do exist.
Do we have to tell our teams?
Yes, and not just for form’s sake. In France, an AI project that affects working conditions goes through information and consultation of the works council, where one exists. And nothing sinks a project faster than a tool discovered after the fact.
Is our company too small for this?
No. Size is not what decides; repetition and a written trail are. A ten-person company handling the same requests every week is good ground to start on.

Sources

  • https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-aipage de la Commission européenne sur le règlement sur l’IA : entrée en vigueur le 1er août 2024, interdictions et maîtrise de l’IA applicables depuis le 2 février 2025, gouvernance et modèles à usage général depuis le 2 août 2025, application générale au 2 août 2026, systèmes à haut risque de l’annexe III au 2 décembre 2027 et systèmes intégrés à des produits réglementés au 2 août 2028
  • https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:02024R1689-20260727règlement (UE) 2024/1689 sur l’intelligence artificielle, version consolidée au 27 juillet 2026 : article 4 (maîtrise de l’IA — obligation de prendre des mesures, sans garantie d’un niveau donné pour une personne) et article 50 (transparence — le système destiné à interagir directement avec des personnes physiques doit être conçu pour qu’elles sachent qu’elles s’adressent à une IA, sauf lorsque cela ressort clairement du contexte, l’obligation pesant sur le fournisseur)
  • https://eur-lex.europa.eu/eli/reg/2026/1744/ojrèglement (UE) 2026/1744 du 8 juillet 2026 modifiant les règlements (UE) 2024/1689, (UE) 2018/1139 et (UE) 2023/1230 (« omnibus numérique sur l’IA »), publié au Journal officiel de l’Union européenne le 24 juillet 2026 et entré en vigueur le 27 juillet 2026 : report des obligations relatives aux systèmes à haut risque (2 décembre 2027 pour l’annexe III, 2 août 2028 pour les produits réglementés de l’annexe I) et réécriture de l’article 4 sur la maîtrise de l’IA en obligation de moyens
  • https://www.cnil.fr/fr/les-fiches-pratiques-iala CNIL publie une série de fiches pratiques sur l’application du RGPD aux systèmes d’IA (base légale, information des personnes, sécurité, annotation, analyse d’impact)
  • https://www.cnil.fr/fr/realiser-une-analyse-dimpact-si-necessairela CNIL précise quand une analyse d’impact relative à la protection des données est obligatoire pour un système d’IA, notamment en présence de profilage ou de décision automatisée
  • https://www.legifrance.gouv.fr/codes/section_lc/LEGITEXT000006072050/LEGISCTA000035609484/code du travail, article L. 2312-8 : le comité social et économique est informé et consulté sur l’introduction de nouvelles technologies et sur tout aménagement important modifiant les conditions de travail
  • https://www.entreprises.gouv.fr/priorites-et-actions/transition-numerique/accompagner-les-entreprises-dans-leur-transition/le-planla Direction générale des entreprises présente le plan national « Osez l’IA » et ses dispositifs d’accompagnement des PME et ETI (diagnostics Data IA, accélérateurs IA), cofinancés dans le cadre de France 2030

So where do you start?

Describe your situation: you get a heading, a scope and a quote in return. No commitment.

Reply within 48 business hours · No commitment · Confidential