Tuesday, shortly after nine. A buyer at a mid-sized machine builder has until noon to check what framework contract TP-118 says about price tiers and notice periods. The company and the contract are a fictional example. The document is long, and the deadlines are scattered across several chapters. Since spring, the intranet has carried one sentence: “AI only after consulting IT.” Who exactly that means, how long an answer takes and what even counts as “AI” is not stated.
The buyer has until twelve. She opens the private account of a public AI service in her browser, pastes in the contract text and asks her question. She means no harm. She wants to finish a task, and the only path open to her at that moment is the one the policy never planned for.
Behind this scene is not the question “AI yes or no.” The question is: Which data may go into which AI? A company that does not answer it leaves the answer to chance. And chance usually means: whichever tool happens to be open in the browser.
Our thesis in one sentence: a ban does not answer this question, but a traffic light with three colors and an approved path for the normal case does. This article shows the model, a decision tree for everyday use, the four typical kinds of data in a mid-sized company, and the link to permissions and approvals. Without that link, any traffic light is decoration.
Why “No AI Without Consulting IT” Is Not a Rule
A rule has to be usable by the person who has the problem right now, within a few seconds and without calling anyone. The sentence from the intranet fails that test for three reasons.
First, it cannot be decided. Consult whom, about what, and does it also apply to the press release someone merely wants to polish? Second, it cannot be enforced. The firewall blocks the company laptop, but the private smartphone is lying next to the keyboard. Third, and most important, it offers no alternative. Someone who has an hour to finish a task and knows no approved path takes the unapproved one.
The pattern has a name: shadow AI, the use of AI tools without the company's knowledge or control. It rarely comes from defiance. It comes from a rule that distinguishes nothing. A ban treats the press release exactly like the salary list. Then every person decides alone, under time pressure and without a yardstick.
| Approach | What happens in daily work | What the company knows about it |
|---|---|---|
| Blanket ban | The work continues on private accounts, unnoticed | Nothing |
| Blanket permission | Each person decides alone, including on salaries and contracts | Little |
| Data traffic light with an approved path | The normal case runs through the approved AI, the exceptions are named | Which tools are in use and where the limits are |
The third row is not a compromise between the first two. It is a different kind of rule: it does not say whether AI is allowed, but which information may go where. That is exactly the distinction a ban lacks.
The Model: Three Colors, Three Paths
The data traffic light classifies information by the damage that results if it ends up in the wrong place. It does not ask about file type, department or whether something “feels important.” It asks: what if this content were in the hands of someone who should not have it tomorrow?
Each color has three parts: a definition, examples from your own company and an approved path. The third part is the decisive one. A traffic light that only says what is not allowed is a ban with colors.
To make the path concrete, we distinguish three destinations for data:
- Public AI services: offerings anyone can open in a browser, where the company has no contract with the provider.
- Company AI: an AI environment the company has commissioned itself, with a data processing agreement, a defined place of storage and processing, permissions taken from the source systems, and a log.
- Protected area: a separated part of the company AI, for example a dedicated source with its own permissions, which only a named, small group may see.
This gives the mapping that applies in daily work:
| Level | Public AI services | Company AI | Protected area |
|---|---|---|---|
| Green | allowed | allowed | allowed |
| Yellow | not allowed | allowed | allowed |
| Red | not allowed | not in the general assistant | only with explicit approval |
| Credentials | nowhere | nowhere | nowhere |
The “Credentials” row deliberately sits outside the three colors. Passwords, keys and access tokens are not content an AI needs in order to help. There is no approved path for them, not even one with approval.
Six properties separate a traffic light people actually use from one that gathers dust in a policy:
- Three levels, not five. Every extra level has to be explained, maintained and, in doubt, delimited from its neighbor. Everyone can keep three levels in their head.
- The level depends on the content, not the file type. A PDF can be a brochure or a termination letter.
- Every level has an approved path. Even red does not end in a bare no, but in the protected area.
- When in doubt, the higher level applies. The cost of an overly cautious call is a detour, the cost of a lax one can be a data leak.
- Examples come from your own company. “Framework contracts of the purchasing department” says more than “confidential documents.”
- One person maintains the traffic light. Without a named owner it is out of date within a year.
Green: What Could Also Be on the Website
The test for green is a thought experiment:
Would it bother us if this content appeared on our website tomorrow?
If the answer is “no,” the content is green. That covers published texts such as product descriptions, press releases and job postings, public standards and laws, and general research questions that reveal nothing about internal matters. Someone who asks how the IP65 protection rating is defined, or what a framework contract means legally, gives nothing away.
Green does not mean every service should be used at will. It means the data is not the limiting factor here. Whether a company permits a specific public service depends on other things: cost, terms of use, copyright questions about the output. For the traffic light, only this holds: with green content, the data does not argue against the service. What counts is what is actually in the input: even a research question is content and can give away internals if it contains project names, prices or customer data. Then it is no longer green.
There is a trap worth raising in every training session. Green plus green does not always make green. Someone who puts a public standard and an internal price list into the same conversation has a yellow conversation. That is why a second rule sits next to the three colors: the highest level in the conversation determines the level of the whole conversation.
Yellow: The Normal Case in a Mid-Sized Company
Yellow is everything that is internal or confidential but not among the highly sensitive data. Framework contracts, quotes, project documents, drawings, bills of materials, customer inquiries, meeting notes, supplier comparisons. This is the material daily work is made of.
That yellow is the normal case has consequences for the whole strategy. An example shows it. Assume a department has twenty tasks in a week where an AI could help. We classify them with the traffic light. The distribution below is an example calculation with round assumptions, not a measurement and not a statement about your company.
| Assumption (example calculation) | Tasks | Share |
|---|---|---|
| Green: published or uncritical content | 7 | 35 percent |
| Yellow: internal or confidential content | 10 | 50 percent |
| Red: highly sensitive content | 3 | 15 percent |
| Total | 20 | 100 percent |
The arithmetic is plain. If a company allows only green tasks as the official path, it has an answer for seven of twenty tasks, which is 35 percent. For thirteen tasks, or 65 percent, there is no approved path. Those thirteen tasks do not disappear, they move into the shadows. If the company instead offers a company AI for green and yellow, it is seventeen of twenty tasks, or 85 percent. Three red tasks remain, and for those there is the protected area.
That is the core argument against the ban. It is not about convenience. It is about the fact that the yellow middle of the work is the largest group, in our example calculation as large as green and red combined, and that a company that does not serve this middle leaves a large part of its AI usage unobserved. What your own distribution looks like, you only know once you count. The exercise for that is at the end of the article.
What the Yellow Path Has to Deliver
A yellow path is only one if the company AI meets certain conditions. Check these five points before the start:
- 1.Contract: If the data includes personal data, you need a data processing agreement under Art. 28 GDPR. A provider that takes you seriously puts it on the table before the start.
- 2.Location: Where is the data stored, where is it processed? With TheroAI, data is stored in Germany and AI processing takes place in the EU. More on this is on the security page.
- 3.Training: Does the contract state that your inputs are not used to train models?
- 4.Permissions: Does the AI answer only from sources that the person asking could open themselves?
- 5.Traceability: Can you see later what the AI did?
If one of these points is missing, the path for yellow is not yet approved. Then you are left with green, and the shadow keeps growing.
Red: Few Data, Clear Limits
Red is the level for information where a leak seriously hits a person or the company. That includes salaries, sick leave records, personnel files and application documents, as well as all data in the special categories of personal data under Art. 9 GDPR, for example health data. Add customers' bank details and credit reports, ongoing settlement or acquisition negotiations, and whatever a company regards as its core secret: a recipe, a manufacturing process, a central algorithm.
Two things matter to us about red.
First: Red has to stay small. If two thirds of the documents are red, the level is worth nothing, and employees treat it like the old ban. In our example calculation it is three of twenty tasks. That is an assumption, but it shows the order of magnitude we mean: few tasks, but clear rules.
Second: Red does not mean “never.” It means “not in the general assistant.” An HR department may work with applications and needs help doing so, just not in the area everyone in the company uses. The approved path is a protected area: a separated source that only a named group may see, with explicit approval by the responsible office and with a log. Whether and how this is permissible in your company is decided by data protection, HR leadership and, where applicable, the works council together, not by IT alone.
One note about the works council tends to come too late in AI projects. A technical installation designed to monitor the behavior or performance of employees is subject to co-determination under section 87 (1) no. 6 of the German Works Constitution Act. Whether a particular AI environment with a logging function falls under it depends on how it is set up. This is not legal advice, so clarify the individual case with your legal counsel. In practice: if you involve the works council in the traffic light early, you save yourself the later dispute over the log.
The Decision Tree for Everyday Use
A model with three colors is quickly explained. It is harder to find the right color in the situation itself. That takes a decision tree that fits on one page in the intranet and next to the input field.
The order of the questions is deliberate. The first question is the one with no exceptions: credentials. Then the question about red, because overlooking red is the biggest mistake. Only after that does the tree ask about green. Everything that is neither stop nor red nor green is yellow. Yellow is therefore not a classification you have to justify actively, it is the default. That eases daily work: someone who is unsure lands in the middle level and has a working path there.
Four examples show how the tree works. All documents are fictional.
| Example (fictional) | Answers to the questions | Level | Where to |
|---|---|---|---|
| Summarize framework contract TP-118 | 1 No, 2 No, 3 No | Yellow | Company AI |
| Answer a customer email about error E-217 on the FL-200 filler | 1 No, 2 No, 3 No | Yellow | Company AI, approve the reply before it is sent |
| Polish a press text about a product launch | 1 No, 2 No, 3 Yes | Green | Any approved AI |
| Align a salary band for an open position | 1 No, 2 Yes | Red | Protected area with approval |
The second example contains an addition we care about. The level governs where data may go. It does not govern what happens to the result. A reply to a customer leaves the building, and for things that go outside, a second check is needed, which we describe below.
Two additional rules belong on the same page as the tree. You already know the first: the highest level in the conversation applies. The second reads: when in doubt, the higher level applies. If you are unsure whether a document is yellow or red, treat it as red and ask. That costs one question. The opposite mistake can cost much more.
Four Kinds of Data in a Mid-Sized Company
The tree provides the method, the company provides the examples. At its core, a mid-sized company has four kinds of data where the AI question keeps coming up: personnel, contracts, engineering and customer data. Each contains green, yellow and red items. The matrix shows the pattern.
The most important sentence about this matrix: no kind of data has one color as a whole. Whoever makes “personnel data” red across the board also locks out the job posting. Whoever makes “contracts” yellow across the board overlooks the negotiation papers. The traffic light belongs on the individual document or document type.
Personnel
The job posting is green, it is published anyway. The organization chart and the training plan are yellow, they are internal but not especially sensitive. Salaries, sick leave records, personnel files and application documents are red. Special rules on employee data protection also apply here. For health data, Art. 9 GDPR applies. And the works council's co-determination belongs in from the start.
Contracts
Published general terms and conditions are green. Framework contract TP-118 from our example is yellow: it contains prices and deadlines, but nothing that hits a person. Here it is worth looking at something often forgotten in practice. Many contracts contain confidentiality clauses. Whether a clause restricts passing information to a service provider, and whether a company AI with a data processing agreement falls under it, has to be checked case by case. Settlement negotiations and anything only a small group may know are red.
Engineering
A data sheet you give to customers anyway is green. The drawing of the FL-200 filler, the bill of materials and the test records are yellow. Red are recipes, process parameters and central algorithms, in other words the knowledge that makes up your lead. The German Trade Secrets Act protects such knowledge only if the company takes reasonable confidentiality measures. A documented traffic light with clear paths is exactly such a measure. Whether it suffices in a dispute is a question for your legal counsel. Engineering is the area where manufacturing companies should look especially closely.
Customer Data
Key figures without names and without any link to individual customers are green. Inquiries, quotes and contacts are yellow. Even a contact in the business customer area is a person with a name and an email address, and therefore personal data under Art. 4 no. 1 GDPR. Bank details and credit reports are red.
The matrix has one more practical use. It is the raw material for training. An hour in which employees write their own document types onto this matrix is, in our view, better invested than any slide of definitions.
The Traffic Light Is Only as Good as the Permissions Behind It
A traffic light says which data may go where. It does not say which data an AI gets to see once it is connected to your systems. That is a second question, and it decides whether the traffic light holds up in daily work.
The simplest example is the forgotten file. For years, a spreadsheet with salaries has sat in an archive folder, never locked because nobody found it. For an AI search, “hard to find” is no hurdle. A yellow or red piece of information in an open folder is therefore effectively green as long as the permissions are wrong. That is why the first action after classification is a check: who may open the folders with yellow and red content?
A good company AI takes over the permissions of the source instead of inventing its own. With TheroAI, the assistant answers only from documents that the person asking could open themselves. The Google Drive connector indexes the users' document permissions along with the documents. That protects against the catastrophe, not against sloppiness: if a folder is open to everyone, it is open to the AI too. The traffic light shows you which folders to touch first. How this looks technically is described on the page about connectors.
Five layers work together, and each has its own owner:
- 1.Classification: The department decides which level a document type has. It knows the content.
- 2.Permissions: The source system decides who may open a document. The AI takes that over.
- 3.Source selection: The person asking chooses what the assistant should answer from.
- 4.Tool rule: The administration sets per tool whether it is allowed, asks first or is blocked.
- 5.Approval and log: What goes outside is confirmed by a person, and the run stays traceable.
Source Selection in the Chat
Source selection is the layer employees hold in their own hands. In TheroAI they open the chat settings at the input field and pick one of five options under “Quellen” (sources).
The options map onto the traffic light. For yellow questions, “Nur Unternehmenswissen” (company knowledge only) is the obvious choice: the assistant answers from internal documents and data. For green research questions, “Nur öffentliche Quellen” (public sources only) fits. “Keine externen Quellen” (no external sources) means the assistant answers from the language model alone, for example when it rephrases a text you pasted in. Whoever picks “Unternehmen und öffentliche Quellen” (company and public sources) combines both worlds in one answer. By the rule “the highest level applies,” the result is then yellow.
The Tool Rule in the Settings
The fourth layer belongs to the administration. In TheroAI, they use the AI tools settings to decide for individual tools and services whether they are allowed, ask first or are blocked. Image generation and web search can be switched on or off organization-wide. Tools that can create, change or delete data carry the “Schreibend” (writing) badge, and “Nachfragen” (ask first) is the obvious setting for them: execution pauses until the person confirms the specific action.
For the traffic light this means: the rule “red not in the general assistant” does not rest on employees' good judgment alone. Where a tool could send or change data, the organization can block it or tie it to a confirmation. In the example shown, the tools for sending emails, drafts and chat messages are set to “Nachfragen” (ask first).
Approval and Log
The fifth layer closes the circle. Yellow content may go into the company AI, but a result that leaves the company, such as a reply to a customer, should be confirmed by a person. Workflows have a dedicated approval step for this. The approver sees the draft and decides, and for replies with more weight the four eyes principle can be switched on. The deadline for the approval is configurable, and in our product captures it is 72 hours. The page on workflows shows what this looks like. Runs of workflows appear in the audit log with time, status and the person involved.
The five layers are not an end in themselves. Each covers a weakness of the others. Classification without permissions stays on paper. Permissions without classification do not know where it hurts. Tool rules without approval only stop the obvious. Only together do they turn the traffic light into a rule that holds in operation.
Introducing It Without Bureaucracy: Six Steps
The traffic light rarely fails because of the idea, but because of the rollout. In our view, a pragmatic sequence works well, and you can adapt it to your company. The steps are a suggestion, not a standard.
- 1.Collect tasks. Ask four or five departments to write down twenty tasks from recent weeks where AI could help, and classify them together. That gives you your own distribution instead of an assumption.
- 2.Fix the examples. Three concrete examples from the company per level and kind of data. They replace any abstract definition.
- 3.Name the yellow path. Decide which company AI applies to yellow, and check the five points above. Without this step, the traffic light is a ban with colors.
- 4.Clean up permissions. Start with the folders holding yellow and red content. Who may open them, and who should not?
- 5.Involve the works council and data protection. Both see the traffic light, the logging and the protected area before they are introduced.
- 6.Publish one page. The decision tree, the matrix with your own examples and the name of the person to ask. Nothing more.
After a quarter, a review pays off: which questions kept coming back? Which document type was disputed? Where was a level too strict, where too lax? The traffic light is a document that moves, and that is exactly what sets it apart from a policy that is adopted once and never touched again.
Five Objections, Answered Honestly
“Isn't that too simple for a serious topic?” The simplicity is deliberate. A rule that only lawyers can apply will not be applied in daily work. The traffic light does not replace legal review, it makes it predictable: the cases that truly need a review end up at red or at the question, not in the browser.
“Is that enough for GDPR?” No, and it does not claim to be. The traffic light is a working tool for the daily decision. A data processing agreement, a record of processing activities and the review by data protection remain necessary. This is not legal advice, so clarify your company's obligations with your legal counsel.
“What if someone uses a private account anyway?” Then it probably happens less often, but it happens. No model prevents every case. What matters is what happens next: in our view, employees report cases more readily when the response is a conversation rather than a warning.
“Who maintains it?” A named person, ideally in data protection or IT, with feedback from the departments. Without an owner, the traffic light is out of date after a year.
“Does it slow the AI down?” The traffic light itself costs seconds, and the tree is built so that it becomes a habit over time. Things get slower at only one point: for anything that goes outside. There, an intermediate step is the price of never having to retrieve a message.
Our Position
The question “Which data may go into which AI?” is not a question of technology but of allocation. A company that answers it does not need a textbook data classification. It needs three colors, a decision tree and an approved path for the normal case.
A ban is the most expensive rule that costs nothing. It costs nothing to introduce and a lot to operate, because it sends the most frequent part of the work into the shadows. An approved path for yellow is not a loosening, it is the condition for being able to enforce red at all. Whoever allows employees the normal case can be strict about the exceptions.
What You Can Take Away
If you start on this topic in your company, these questions and steps help:
- Can your employees decide within 30 seconds which data may go into which AI, without calling anyone?
- Is there an approved path for the normal case, meaning yellow data, and does it meet the five points of contract, location, training, permissions and traceability?
- Have you explicitly excluded credentials, including for the protected area?
- Are the folders with yellow and red content permissioned the way you intended, and not the way they historically grew?
- Who confirms results that leave the company, and how long does that person have to do so?
- Is the works council involved before the traffic light is introduced?
And one exercise for this week: have each department write down twenty tasks where AI could help, and assign them to the three colors. If more than half are yellow, you know where your approved path has to start.
If you would like to see how permissions, source selection, tool rules and approvals fit together in a company AI, we are glad to show you with sample data, without pressure and without obligation: see the demo.
See Thero live
Book a short demo. You talk directly to the founding team.