AI Policy
1. Purpose and Scope
This AI Policy governs the responsible use of artificial intelligence (AI) at Nextra Consulting GmbH (hereinafter “Nextra”). It applies to all employees with regard to the use of AI in internal processes and client projects.
The objective is to,
- efficiently leveraging the opportunities offered by AI,
- minimize legal, ethical, and data privacy risks, and
- ensure transparency and quality in consulting.
2. Principles for AI Use
The use of AI at Nextra follows these fundamental principles:
- Responsibility: Decisions with significant impact must not be made solely by automated AI systems.
- Ethical Principles: The use of AI must comply with internal company and societal values. Discriminatory or manipulative content is prohibited. AI must not be used for deception.
- Transparency: The use of AI will be disclosed internally and – if relevant – to clients.
- Private Accounts: For business-related AI use, only accounts provided or approved by the company are to be used. Private accounts are not permitted.
- Explainability: Employees must be able to explain and justify the content of work results created with AI support.
- Purpose Limitation: AI is used exclusively for clearly defined, legitimate purposes.
- Human-in-the-Loop: Professional assessment and responsibility always remain with Nextra employees.
3. Permitted Areas of Use
AI may be used for, among other things:
- Research and analysis support
- Structuring, summarizing, and preparing information
- Drafts for texts, concepts, or presentations
- Automation of repetitive tasks
- The final professional review, evaluation, and approval are always carried out by Nextra employees.
4. Prohibited or Restricted Use
Specifically prohibited is:
- the unverified adoption of AI results into client deliverables,
- the processing of sensitive or personal data without a legal basis,
- training external AI systems with confidential client or company data,
- the use of AI for discriminatory, misleading, or unlawful purposes.
5. Data Protection and Confidentiality
When using AI, applicable data protection and confidentiality requirements must be observed:
- Personal data may only be processed if there is a permissible legal basis for doing so.
- Client and company data must be treated confidentially and may only be processed in approved tools.
- It must be ensured that no uncontrolled disclosure or storage of sensitive information occurs.
6. Use of AI in Client Projects
- The use of AI in client projects is project-specific and purpose-bound.
- Clients will be transparently informed about the nature and scope of AI use, if relevant for the project.
- AI does not replace professional consulting but serves as a supporting tool.
7. Quality Assurance
- AI-generated content must always be critically reviewed.
- Sources, assumptions, and results must be validated, especially for strategic or regulatory issues.
- The same quality standards apply to client deliverables as to non-AI-supported services.
8. Approval Process
Before the initial use of an AI tool, an assessment is required. This includes a formal review (e.g., CE marking) as well as a substantive risk assessment (risk class according to the EU AI Act). The result of the risk impact assessment will be documented in writing and forms the basis for approval. Unapproved tools may not be used.
9. Competencies and Responsibility
- Employees may only use AI within the framework of this policy.
- Nextra promotes competent handling of AI through training and knowledge exchange.
10. Further Development of the Policy
This AI Policy will be regularly reviewed and adjusted as needed, particularly in response to new regulatory requirements or technological developments.
Responsible for adaptation, communication, and control: Dr. Martin Granzow
Questions regarding application and interpretation should be directed to: Dr. Martin Granzow
Status: April 2026