AI for small and midsize companies without an IT department
A practical blueprint for AI automation without an IT department: 10 use cases, a 30-60-90-day plan, a minimum governance standard, and concrete savings.
By SIMO GmbH
Thirty-six percent of German companies use artificial intelligence, but only 19 percent of small and midsize companies do. The gap is real, and the reasons are understandable: legal uncertainty (53 percent), lack of know-how (53 percent), and lack of resources (51 percent). That is what the current Bitkom study on AI use in Germany shows.
No budget for an IT department, no development team, yet growing pressure: that is the starting point for most businesses with 5–250 employees. This article provides the blueprint that changes it.
AI for small and midsize companies: what does it mean in practice?
AI is not a monolith. In the day-to-day work of small and midsize companies, it is rarely about self-trained models or data science teams. What realistically works in practice falls into three categories:
Generative AI such as ChatGPT or Claude: writing, summarizing, translating, and structuring text. The biggest quick win for almost any business.
Automation AI: workflows that move, check, and evaluate data between tools, often with n8n, Make, or Zapier. This is where small and midsize companies gain the most, because repetitive processes can be eliminated without anyone writing code.
AI as a feature in standard software: DATEV, Lexoffice, HubSpot. These vendors are building in AI features that many businesses already pay for but do not yet actively use.
Why the combination of automation and AI is decisive: AI alone rarely solves a problem. Real time savings only come once AI is embedded in a working workflow. The difference between “I sometimes use ChatGPT” and “my proposal process runs semi-automatically” lies in exactly this step.
Status quo: where do German small and midsize companies really stand?
According to IfM Bonn, AI use in German small and midsize companies rose by 8 percentage points from 2023 to 2024, to 19 percent. That sounds like progress, and it is. But among large companies, almost every second one uses AI. The gap is widening, not closing.
Particularly worrying: 4 in 10 companies assume that employees use private AI tools at work, so-called shadow AI. Only 23 percent have any rules for it. That is not an AI problem; it is a governance problem. And it can be solved.
The 7 biggest obstacles, and how to overcome them without IT
1. Legal uncertainty
The EU AI Act applies. But most processes in small and midsize companies do not fall into a high-risk category. Proposal automation, document filing, and communication are not high-risk applications within the meaning of the act.
2. GDPR and data protection
This can be solved with a clear choice of tools: GDPR-compliant providers, data processing agreements (DPAs), and no customer data in public LLMs without review.
3. Poor data quality
Honestly, this is the real number one obstacle in practice: a desert of Excel files, PDF archives, and no consistent structures. The 30-day plan below addresses this problem explicitly.
4. Missing interfaces
In most cases, n8n solves this. If a tool has an API, n8n can talk to it. If not, there are workarounds via email or webhooks.
5. Lack of staff
That is why a project lead’s mindset is decisive: you do not have to be able to implement everything yourself. You have to know what you want, who or what will implement it, and how to check whether it works.
6. Team acceptance
Shadow AI shows that employees want to use AI; they just have no official way to do so. Offer them one: with a policy, tool access, and a short training session, it moves faster than expected.
7. Unclear ROI
Measure ROI from day one with concrete metrics. Not “AI somehow helped us,” but “proposal creation: 45 minutes before, 12 minutes now, measured since week 3.”
EU AI Act: what small and midsize companies really need to do now
Article 4 of the EU AI Act has applied since February 2, 2025, and it is not optional. As amended in July 2026, it requires every company that uses AI to take measures that support its staff’s AI literacy (as of October 2026 · not legal advice). Not as a certificate, but role-specific and documented.
In practice, this means you need a list of who in the business uses (or is meant to use) AI tools, and proof that these people have received basic training. Two hours of workshop plus a record are enough as a minimum standard for small and midsize companies without high-risk applications.
The timeline: the rules for general-purpose AI models have applied since August 2025, the transparency obligations since August 2026, and the high-risk obligations apply under Regulation (EU) 2026/1744 from December 2, 2027 (as of October 2026 · not legal advice). Starting now leaves enough buffer.
10 use cases without an IT department: effort and benefit
- Process: Proposal creation from project data | Tool stack: n8n + LLM + CRM | Effort (days): 3–5 | Benefit: 3–5 hrs/week | Risk level: Low
- Process: Receiving and booking e-invoices | Tool stack: DATEV + n8n | Effort (days): 2–3 | Benefit: 2–4 hrs/week | Risk level: Low
- Process: Sending order confirmations automatically | Tool stack: n8n + email | Effort (days): 1–2 | Benefit: 1–2 hrs/week | Risk level: Low
- Process: Classifying incoming inquiries | Tool stack: n8n + LLM | Effort (days): 2–3 | Benefit: 3–4 hrs/week | Risk level: Low
- Process: Document filing and tagging | Tool stack: n8n + DMS | Effort (days): 3–5 | Benefit: 4–6 hrs/week | Risk level: Medium (GDPR)
- Process: Weekly report from time tracking | Tool stack: n8n + LLM | Effort (days): 2–3 | Benefit: 1–2 hrs/week | Risk level: Low
- Process: Company GPT / internal knowledge assistant | Tool stack: RAG + LLM | Effort (days): 7–14 | Benefit: 5–10 hrs/week | Risk level: Medium
- Process: Template-based customer communication | Tool stack: n8n + LLM | Effort (days): 2–4 | Benefit: 3–5 hrs/week | Risk level: Low
- Process: Checking supplier invoices | Tool stack: n8n + OCR + LLM | Effort (days): 4–7 | Benefit: 3–5 hrs/week | Risk level: Medium (GDPR)
- Process: Onboarding new employees | Tool stack: n8n + forms + LLM | Effort (days): 5–8 | Benefit: 4–6 hrs/month | Risk level: Medium (HR)
30-60-90-day plan: implementation with a project lead’s mindset
Days 1–30: governance and a first pilot
The first two weeks belong to structure, not technology. That sounds dry, but it is the difference between a pilot that lasts and one that fades away after six weeks.
Concrete steps:
- Write a tool policy: which AI tools are allowed, and for which data?
- Set up official access, for example ChatGPT Team or Claude
- Document AI literacy training: a short training session for all users
- Choose a single process as the pilot, ideally one with high volume and low risk
Case example: the managing director of a timber construction company started exactly this way, having proposal templates filled automatically from project parameters. Effort for the first pilot: four days. Result: proposal creation cut from 45 minutes to 12 minutes. After 30 days, the system was stable and documented.
Days 31–60: integration and measurement
Now pilots two and three are added. The key: measure first, then scale. How long did the first process take before? How long does it take now? What is the hourly rate? This gives you a concrete ROI, which is then communicated internally.
Case example: in this phase, a timber construction company automated its incoming invoice check. The n8n workflow reads incoming e-invoices (XRechnung format, mandatory to receive since January 2025), matches line items against the order, and flags discrepancies. What used to take 3–4 hours a week now runs automatically, with human review for discrepancies above 5 percent.
Days 61–90: scaling and operating model
Anyone who has made it this far has three automations running, a documented AI literacy concept, and first ROI figures. Now the task is to turn this into an operating mode:
- Who is responsible for which workflows?
- Who regularly checks whether the outputs are still correct?
- How is it documented?
Case example: in this phase, a window company built an internal knowledge assistant, a company GPT for product configurations and installation notes. The team asks the assistant technical questions and gets answers based on the company’s own documents.
Governance: the minimum standard for small and midsize companies
What should be in place, and what is already enough:
- A list of approved tools and what they are used for
- A data classification: which data may be entered where (no unredacted data from personnel files in public LLMs)
- Prompt guidelines for frequently used applications
- Human-in-the-loop review for all outputs that go outside the company
- A deletion concept for AI-generated content that does not need to be retained
Case example: a furniture design firm solved this with a one-page internal policy, printed out, discussed once, and filed. That is enough as a starting point and can be expanded later.
Topics in more depth
For specific areas, there are further resources:
- GDPR and data processing for AI tools: which contracts you need and what works with public LLMs
- Building RAG and a company GPT: an internal knowledge assistant step by step
- DMS automation: filing, tagging, and finding documents automatically
- Automating order management: from receipt to confirmation without manual steps
- Automating e-invoicing: integrating XRechnung and ZUGFeRD into the workflow
- Measuring ROI: hourly rate, time saved, payback calculation
- Choosing tools: n8n vs. Make vs. Zapier for small and midsize companies without IT
Conclusion
AI for small and midsize companies is neither a prestige project nor a distant prospect. It is a craft, with a plan, measurement, and the mindset of a project lead rather than a programmer. Thirty days to the first running pilot. Ninety days to a working operating model.
The obstacles (legal issues, know-how, resources) can be overcome if you tackle them in the right order. And the pressure to start now is real: the AI literacy rule since February 2025, e-invoicing since January 2025, and shadow AI growing every month.
Frequently asked questions
What does AI mean for small and midsize companies in practice?
In most cases, it means generative AI for texts and summaries combined with automation workflows for recurring processes. No development team is needed: businesses with 5–250 employees can achieve real time savings with tools such as n8n, ChatGPT, and industry-specific software without building their own IT infrastructure.
How long does it take to get started with AI automation?
A first working pilot, such as automated proposal creation or an incoming invoice check, can be implemented in 3–7 days. A stable, documented system with two or three automations running is realistic within 30–60 days.
What does a small or midsize company need to do now because of the EU AI Act?
Article 4 on AI literacy has applied since February 2, 2025, and in amended form since July 2026. Companies take measures that support their staff’s basic skills in using AI tools and keep a record of them. A two-hour workshop plus a record is a practical starting point.
Which processes are best suited as a first pilot?
Processes with high volume (repeated daily or weekly), clear inputs and outputs (no room for interpretation), and low risk (no sensitive personnel data, no direct customer contact without review). Proposal creation, order confirmation, incoming invoices, and document filing are typical candidates.
What is shadow AI, and why is it a risk?
Shadow AI is the private use of AI tools by employees without the company’s knowledge or approval. The risk: customer data, contract information, or internal documents end up in public LLMs without a data processing agreement. The answer is not a ban but official access with a clear policy.
Do I need programming skills?
No. Tools such as n8n or Make can be used through graphical interfaces. What you need is an understanding of your own processes and the ability to describe, test, and review workflows.
Sources
How our articles are created and who is accountable for them is set out in our editorial standards.
