← Back to whitepapers

White paper · June 2026

White paper — Generative AI in the enterprise: stakes and prerequisites

Generative AI in the enterprise: stakes and prerequisites. 39 pages to move from demos to uses that hold, without exposing the company — with no conflict of interest: Clarendis sells no model, no AI platform, and takes no referral commission.

  • The AI Act in plain words, with GDPR, intellectual property and trade secrets — and their Swiss counterparts
  • The vendor requirements grid and the full cost, beyond the headline price
  • The blind spots: shadow AI already installed, the leak through prompts, the plausible error in production, the evaluation never done
  • The 90-day action plan — see clearly, frame and equip, prove one case end to end — with its five-number dashboard
Cover of the white paper
White paper · June 2026
White paper — Generative AI in the enterprise: stakes and prerequisites

Read the opening pages

The 39 pages of this white paper. The first 11 are readable in full; the rest is sent by email.

Page 1 of the white paper “Generative AI in Business: Challenges and Prerequisites”
Page 1

White paper · June 2026

Generative AI in the enterprise: stakes and prerequisites

Moving from demos to uses that hold — without exposing the company

“The companies that end up disappointed are not the ones that picked the wrong model — they are the ones that believed the model was the project.”

3 uses

4 prerequisites

90 days

That already pay off, everywhere — and the method for telling them apart from demos

Data, access rights, the framework, skills — what the demos never show

The action plan, from mapping actual uses to the first end-to-end proven case

This white paper draws on the digital-steering experience of the Clarendis network, in France and in Switzerland; it reads on its own, and rewards re-reading at every new AI project.

Page 2 of the white paper “Generative AI in Business: Challenges and Prerequisites”
Page 2

Contents

Foreword 03 Executive summary — the document in ten statements 04 Your reading path 06 1 The generative-AI misunderstanding The model is not the project · What the technology can do — and what it will not · What the status quo costs · The three houses: equip, integrate, operate in a regulated sector 07 2 The framework: what the law already requires The AI Act, in plain words · GDPR and personal data · Intellectual property and trade secrets · The usage charter that actually serves · What converges — and the Swiss counterparts 12 3 The prerequisites: data, access, architecture Enterprise data, worksite no. 1 · Access rights, revealed by AI · Plugging AI into your documents, plainly explained · Buy, assemble or build · The vendor-requirements grid · The full cost 17 4 The blind spots The shadow AI already installed · The leak through prompts · The plausible error in production · The evaluation never done · Vendor dependence · The business that doesn't believe — or believes too much · The automated customer decision 22 5 Deciding without predicting What is written, what is not · From assistants to agents: the rule that covers both · From experimentation to value · The four no-regret decisions 28 6 The 90-day action plan Where are you starting from? · D1-D30: see clearly · D31-D60: frame and equip · D61-D90: prove — one case proven end to end · The dashboard: five numbers 31 Moving to execution 35 Appendices — Glossary, sources, about Clarendis 36-38

Page 3 of the white paper “Generative AI in Business: Challenges and Prerequisites”
Page 3

Foreword

Generative AI lives a paradox. No technology has ever been adopted this fast by individuals — your employees already use it, with or without your blessing — and never has the gap been this wide between the enthusiasm of the demos and the scarcity of uses that hold in production. The two symmetrical complaints of the moment: “our pilots never scale” on the leadership side; “everything is forbidden, so we do it without saying so” on the team side. Enthusiasm and control are two faces of the same subject: the journey of the company's information through tools that transform it. And almost everywhere, they are entrusted to conversations that never meet.

This white paper was born of a market-wide observation: generative-AI projects that disappoint rarely stumble on the model — they stumble on data no one can find, access rights never laid flat, and uses never evaluated. The models exist, the tools exist, the legal framework is being written. What is missing is a method that puts the prerequisites before the promises, and that is what this document offers: the misunderstanding first (chapter 1), the framework (chapter 2), the prerequisites (chapter 3), the blind spots (chapter 4), deciding under uncertainty (chapter 5), and an executable plan (chapter 6).

A point of intellectual honesty: we sell no model, no AI platform, and we take no referral commission. This document does not predict the technology — it records what works today and what the texts require; what comes from field experience is flagged as such, and what remains uncertain is named as uncertain.

How to read this document. The chapters stand alone. If your teams already use AI tools with no framework, start with chapter 4. If a project is under way and stalling, chapter 3 will probably tell you why. If the executive committee asks “what is our AI position?”, chapters 1 and 5 build it. Each chapter closes with the same box, what this changes for you, written for three readers: the chief executive, the CIO, the risk-and-compliance lead. Deliberately the same subject seen from three seats — because these projects fail precisely where leadership, technology and compliance do not share the same map.

Enjoy the read — and may your uses hold.

Cédric Guittard

Anna Hoang

cedric.guittard@clarendis.com

anna.hoang@clarendis.com

for the Clarendis team

Page 4 of the white paper “Generative AI in Business: Challenges and Prerequisites”
Page 4

Executive summary

The document in ten statements. Each is developed and sourced in the chapter indicated.

1

2

The model is not the project. The project is the journey of your information: what data goes in, who sees it, what is done with the answer, who answers for it. The model is only one link — and the easiest one to swap. (Chapter 1)

Generative AI is already inside your company. With or without an official project, your teams use it — personal accounts, documents pasted into consumer tools. The question is not “should we go?” but “how do we regain control of what already exists?”. (Chapters 1, 4)

3

4

The framework is no longer a prospect, it is a calendar. The European AI Act is in force and applies in stages; GDPR, intellectual property and trade-secret law apply already, without waiting. (Chapter 2)

The first worksite is not the tool, it is your data. An AI plugged into outdated, duplicated, badly filed documents produces outdated, duplicated, badly filed answers — confidently. Documentary quality becomes a condition of production. (Chapter 3)

5

6

AI reveals your access rights. An assistant that reads every company document gives each person what their rights allow — including what they have allowed by mistake for years. Laying access flat is a prerequisite, not a refinement. (Chapter 3)

The plausible error is this technology's own risk. Generative AI does not fail like software — it fails with confidence. Any production use requires evaluation before, supervision during, and a human accountable for the answer. (Chapter 4)

Page 5 of the white paper “Generative AI in Business: Challenges and Prerequisites”
Page 5

7

8

Banning does not protect — framing does. A blanket ban manufactures shadow AI, invisible and uncontrolled. A short charter, validated tools actually provided, and one simple rule on what never leaves the company protect better than three memos. (Chapters 2, 4)

The safe value is internal and assisted. The uses that pay off everywhere today assist teams — drafting, summarising, document search, support — with a human in the loop. Automated customer-facing decisions, by contrast, await guardrails few organisations have. (Chapters 4-5)

9

10

Dependence is decided now. Models, platforms and prices move fast; the architecture that isolates the model behind an exchange layer — so it can be swapped without a re-project — is the only insurance robust in every scenario. (Chapters 3, 5)

The constraint hides an asset. The prerequisites AI imposes — clean data, controlled access, evaluated uses — are exactly the worksites the company kept postponing. AI is the occasion to fund them; they will outlive every model. (Chapter 5)

Where to start, depending on your situation:

Nothing is framed, everyone uses it. Chapter 4 (shadow AI, the leak through prompts), then straight to the 90-day plan in chapter 6. Your absolute priority: the census of actual uses and the charter paired with validated tools.

A project is under way and stalling. Chapter 3: data, access and evaluation are the three places where your schedule is probably lying — rarely the choice of model.

The board asks for a position. Chapters 1 and 5: what the technology can do, what the law requires, what is robust in every scenario. The four no-regret decisions of §5.4 fit on a one-page memo.

Page 6 of the white paper “Generative AI in Business: Challenges and Prerequisites”
Page 6

Your reading path

Three marked itineraries. The “What this changes for you” boxes at the end of each chapter are written for your seat.

CEO Chief executive 25 minutes

CIO CIO / CTO 1 h 30

RISK Risk & compliance 1 hour

Full document recommended. Your critical path:

01 Executive summary

You live this subject daily. Your path:

02 chapter 1 (§1.3: what the status quo costs, in business language)

01 chapter 3 in full (data, access, architecture, the vendor grid)

01 chapter 2 in full (AI Act, GDPR, IP, the charter that serves)

03 chapter 5 (deciding without predicting — rules, not forecasts)

02 chapter 4 (your blind-spot map — evaluation first)

02 chapter 4 (the seven blind spots — your audit plan for the year)

03 chapter 2 (the framework becomes your requirements list)

04 chapter 6, §6.4 (the five numbers of your monthly agenda).

03 chapter 3, §3.2 (access rights: where AI exposes the existing)

04 chapter 5, §5.4 (the 2026 technical choices that commit 2030)

You will know what to fund, what to demand, and how to check it is moving.

04 the six “Risk & compliance” boxes, at the end of each chapter.

05 chapter 6 in full — the plan is yours.

What you came looking for

Need

Where

In what form

A map of the legal framework that fits on one page

Chapter 2

AI Act, GDPR, IP, trade secrets: who requires what, what converges — and the Swiss counterparts

The prerequisites the demos never show

Chapter 3

Data, access, the architecture that isolates the model, the vendor grid, the full cost

The blind spots of official programmes

Chapter 4

7 situations, each with its revealing question and its first move

A plan executable tomorrow

Chapter 6

90 days in three phases, one case proven end to end, five numbers

Page 7 of the white paper “Generative AI in Business: Challenges and Prerequisites”
Page 7

Chapter 1

The generative-AI misunderstanding

1

Before talking models and platforms, the subject must be freed from its founding misunderstanding — believing generative AI is a matter of tools — and anchored in what it is: a journey of the company's information.

1.1 The model is not the project

T hree years of generative AI have produced a reflex: for every announcement, a demo; for every demo, a pilot; for every pilot, a quiet disappointment. The market's most constant finding: the average company does not lack use-case ideas — it lacks the prerequisites that turn a demo into a use that holds : findable data, controlled access, honest evaluation, a named owner.

Generative AI is not a collection of tools: it is a journey. A piece of company information enters somewhere (a question, a document, a client file), passes through a model that transforms it, and comes out as a decision, a text or an action that commits someone. Every link of that journey raises exactly two questions: is the answer useful and correct? — that is value; is the information protected and the use owned? — that is control. Two questions, one journey: that is why this document treats both together.

This reversal has an immediate practical consequence: the first deliverable of an AI programme is not a tool choice — it is a map of uses, actual and desired. Who uses what, today, with which data; which uses would create value tomorrow, on which tasks, at what level of risk. That map — one page per department is enough — is the most profitable document of chapter 6, and the one most often missing from the programmes we see stall.

A market-wide observation. When a company takes its first census of actual generative-AI uses across its teams, the count almost always far exceeds what leadership imagined — personal accounts, browser extensions, documents translated or summarised in consumer tools. No malice anywhere: the tool simply arrived faster than the framework. It is the most common starting point, and it is not shameful — it is just urgent.

Page 8 of the white paper “Generative AI in Business: Challenges and Prerequisites”
Page 8

1

Chapter 1 — The generative-AI misunderstanding

1.2 What the technology can do — without jargon

To decide, there is no need to understand neural networks — three properties suffice, and they explain everything else in this document.

It excels at language. Drafting, summarising, translating, rephrasing, extracting the essence of a document, answering a question about a supplied text: on these tasks the quality is real, measurable, and available today. That is where the uses that pay off everywhere live — assisting teams with their writing and their document searches.

It produces the plausible, not the certified. The model generates the most likely answer — most often right, and sometimes wrong with the same confidence. This property is not a teething defect the next version will erase: it is the nature of the technology. It imposes the rule that runs through this document: the more the answer commits, the more a human verifies.

It knows only what it is given. A model knows neither your customers, nor your contracts, nor your procedures — unless it is given them, at question time or by plugging it into your documents (chapter 3). It is the property with the heaviest consequences: the quality of your answers will be the quality of your documentation , and every piece of information supplied to the model is information leaving its original location — hence chapters 2 and 4.

Language

Plausible

Your data

Draft, summarise, search — today's safe value

Not certified — the more the answer commits, the more a human verifies

The model knows only what it is given — and what it is given leaves

The whole market vocabulary — RAG, agents, fine-tuning — comes down to these three properties; the glossary at the end of this document translates it once and for all. Nothing more technical will be required from here on.

Page 9 of the white paper “Generative AI in Business: Challenges and Prerequisites”
Page 9

1

Chapter 1 — The generative-AI misunderstanding

1.3 What the status quo costs

The status quo — no framework, no tools provided, no position — has a cost, but it is scattered, and therefore invisible to budgets. Making it visible is the first act of governance:

The cost of exposure. Without validated tools, teams use their own: internal documents, customer data, elements of strategy leave every day for consumer services, under personal accounts, outside any contract. This is not a hypothesis — it is the default state of any organisation that has provided nothing.

The cost of the gap. Productivity gains on language tasks are real and already quantified by those who measure them. The gap widens silently: between your teams and your competitors', and inside your teams, between those who equipped themselves and the rest — with nothing reporting upward.

The cost of the false start. The other side: the pilot launched under the spotlights, without prerequisites, that disappoints — and vaccinates the organisation for two years. A false start costs more than a delayed start: it spends the credit the real project will need.

3 costs

1 map

2 questions

Exposure · gap · false start — to be objectified in your own findings

Of actual and desired uses — the first deliverable, before any purchase

Useful and correct? Protected and owned? — on every use

1.4 Who this document is for

We write for three houses that share the same questions with different stakes: the company equipping its teams (function productivity — most companies' way in), the company integrating AI into its offering (product, customer service, content — where the error becomes visible to the customer), and the company in a regulated sector (finance, health, legal — where chapter 2's framework weighs double). The principles are common; where a recommendation diverges by house, we flag it.

One conviction to close this chapter: generative AI serves a simple promise — that your teams spend their time on what only humans can do, and that your information serves you alone. Every page that follows is judged against it.

Page 10 of the white paper “Generative AI in Business: Challenges and Prerequisites”
Page 10

1

Chapter 1 — The generative-AI misunderstanding

1.5 The three houses, in practice

The principles of this document are common; how they are implemented differs profoundly by house. For each: the most profitable entry point, and the most frequent mistake:

House

The profitable entry point

The frequent mistake

The chapter to read twice

Equipping its teams — function productivity

One validated tool provided to all, a short charter, and three assisted uses measured — before any platform

Banning without providing: use continues, invisible, on personal accounts

Chapter 4 — shadow AI

Integrating into its offering — product, customer service

Evaluation before production: a set of real cases, a quality threshold, named human supervision

Exposing the plausible error to the customer with no net — trust lost costs more than the gain

Chapter 4 — the plausible error, evaluation

Regulated sector — finance, health, legal

The usage register and AI Act qualification from the first case — compliance as a condition of opening, not of closing

Waiting “for the framework to settle”: it is written, and the competition is not waiting

Chapter 2 — the framework, in plain words

Three houses, one thing in common: none starts from zero. The uses already exist, with or without a framework; the question is never “launch or not” but “regain control of what, in which order”. That is precisely what chapter 6's plan sequences.

For the smallest organisations. If you have neither a CIO nor a lawyer, the document still reads in an hour via the “Chief executive” path — and chapter 6's plan reduces for you to five moves: one validated tool provided to all, a one-page charter, the rule of what never leaves, three assisted uses measured, and a quarterly review. That is already 80% of the way.

© Clarendis — June 2026 10

Page 11 of the white paper “Generative AI in Business: Challenges and Prerequisites”
Page 11

1

Chapter 1 — The generative-AI misunderstanding

The dated-decision template, to copy as is

As in every volume of this collection, everything starts with a signed page. On AI it has an extra virtue: it replaces the implicit position — silence, which everyone interprets their own way — with an explicit, dated position everyone can apply.

Decision to bring generative-AI uses under control

“[Date]. The management of [company] decides to bring generative-AI uses under control: value and protection of information, run as one programme. [First name Last name] is appointed its owner. Milestones: map of actual and desired uses within 30 days; charter published and validated tool provided within 60 days; first use proven end to end — measured, evaluated, documented — within 90 days. A dated log of incidents and decisions is opened as of today. Signature.”

This text is sent to no one: it is an internal note. It dates your trajectory — useful the day an incident or a client questions your position, indispensable to your teams as of today. Five dated lines are worth more than ten pages never signed.

What this changes for you

CEO

CIO

RISK

Chief executive. Sign the dated decision above this week — one page, one owner, three milestones. And ask the two-number question: how many employees already use generative AI, and how many with a tool the company provides. The gap is your real roadmap.

CIO. The first deliverable is the map of uses, not a model comparison. One page per department: who uses what, with which data, for which task — and which uses would create value tomorrow. Chapter 3 gives you the grid for what follows.

Risk & compliance. The same map of uses is your register in the making — the one the AI Act and GDPR will ask you to keep. Every unlisted use is both a possible leak and an uninstructed file: you now share an argument with the CIO to obtain it.

© Clarendis — June 2026 11

The remaining 28 pages are in the complete document.

Download the white paper
Page 12, blurred — available in the full document
Page 12 · in the full document
Page 13, blurred — available in the full document
Page 13 · in the full document
Page 14, blurred — available in the full document
Page 14 · in the full document
Page 15, blurred — available in the full document
Page 15 · in the full document
Page 16, blurred — available in the full document
Page 16 · in the full document
Page 17, blurred — available in the full document
Page 17 · in the full document
Page 18, blurred — available in the full document
Page 18 · in the full document
Page 19, blurred — available in the full document
Page 19 · in the full document
Page 20, blurred — available in the full document
Page 20 · in the full document
Page 21, blurred — available in the full document
Page 21 · in the full document
Page 22, blurred — available in the full document
Page 22 · in the full document
Page 23, blurred — available in the full document
Page 23 · in the full document
Page 24, blurred — available in the full document
Page 24 · in the full document
Page 25, blurred — available in the full document
Page 25 · in the full document
Page 26, blurred — available in the full document
Page 26 · in the full document
Page 27, blurred — available in the full document
Page 27 · in the full document
Page 28, blurred — available in the full document
Page 28 · in the full document
Page 29, blurred — available in the full document
Page 29 · in the full document
Page 30, blurred — available in the full document
Page 30 · in the full document
Page 31, blurred — available in the full document
Page 31 · in the full document
Page 32, blurred — available in the full document
Page 32 · in the full document
Page 33, blurred — available in the full document
Page 33 · in the full document
Page 34, blurred — available in the full document
Page 34 · in the full document
Page 35, blurred — available in the full document
Page 35 · in the full document
Page 36, blurred — available in the full document
Page 36 · in the full document
Page 37, blurred — available in the full document
Page 37 · in the full document
Page 38, blurred — available in the full document
Page 38 · in the full document
Page 39, blurred — available in the full document
Page 39 · in the full document
Share this white paper