How it works today with most vendors
The AI comes included. It is part of the subscription, the product page says it works "GDPR-compliant", and the interface has a button that produces a draft text. Nobody has to set up access, nobody has to pick a model, nobody has to read a contract. That is convenient, and in a demo it is the strongest argument the vendor has.
The bill for it sits in a place that is rarely read. The data processing agreement contains a list of sub-processors, and the name of the AI provider is in it – often together with a data center location outside the EU and a reference to standard contractual clauses. That contract is not yours. You did not negotiate it, you cannot change it, and you learn exactly as much about its content as the vendor wrote into that list.
In operation this makes itself felt in three ways. If the vendor switches the model, because a new one is cheaper or an old one is discontinued, the output changes without anyone being asked: wording comes out differently, risk suggestions come out differently, and the quality you reviewed three months ago is no longer the same. If a supervisory authority or a customer asks where the content of a processing activity is transmitted, you have to ask the vendor instead of looking in your own records. And if a group policy prescribes one provider or prohibits another, exactly one option remains: switch the feature off and do without it.
On top of that comes the vagueness of the marketing claim. "GDPR-compliant" is not a property a software vendor can confer on an AI service. A transmission becomes lawful because you, as the controller, have reviewed and documented the legal basis, the purpose, the recipient and any third-country transfer. Nobody owes that review in your place, the software vendor included.
The moment it becomes visible
In day-to-day work it does not become visible. It becomes visible in three situations. During your own vendor review, when a questionnaire wants to know which subcontractors are involved in the processing and on what basis. With a group requirement that contains a list of approved AI providers on which the included one does not appear. And when the legal department asks on what basis content from the records of processing activities goes to a third country.
In all three cases the question is not "Do you use AI?" but "Who is the provider, what does the contract say, and who decided that?" An included AI has no answer to that question that comes from your own organization.
The analysis
What the Included AI Costs
The five points do not depend on the quality of the model. They arise because the decision about the provider is not taken where the responsibility sits.
View AI use cases in preecoThe vendor makes the decision, you carry the responsibility
Who receives the transmitted content is determined by the software vendor. Accountability for that transmission stays with your organization. You are therefore documenting a choice you did not make.
No influence over a change of model
Models are discontinued and replaced by newer ones. If the vendor switches, the output changes without anyone being asked. A quality once reviewed and a transmission once reviewed no longer hold unchanged after that.
Third-country transfer and training assurances are not negotiable
You take what the data processing agreement of the vendor says. Whether transmitted content may be used for training and in which country it is processed is therefore predetermined. You have no negotiating position of your own towards the AI provider.
A self-hosted model cannot be connected
Anyone who has to keep content in-house cannot use an included AI. Public authorities, hospitals and groups running their own models are therefore locked out of the feature. The way out is usually to do without, not to configure.
No evidence of which call went where
Without a log the use cannot be reviewed. You can neither show how often and by whom the feature was used, nor demonstrate to an auditor which model was addressed at which point in time. The statement remains an assertion.
The target process in six steps
Model-agnostic means: the software brings the interface, you bring the provider. These six steps separate the two sides cleanly – no matter which provider you decide on.
1. Choose the provider deliberately. The options are OpenAI, Langdock or any OpenAI-compatible endpoint, including a self-hosted one. The decision belongs on record with its reasons: which provider, which place of processing, which alternative was rejected.
2. Sign the contract yourself. The data processing agreement, the review of any third-country transfer and the assurances about training with transmitted data are yours. That is the additional work, and it belongs exactly where your other service providers sit: in your own vendor review and in the records of processing activities.
3. Store the access and test it. You enter your own API key. It is stored encrypted and shown only masked in the interface. On saving, a connection test runs against the configured model, so a wrong key shows up immediately instead of only at the first real attempt.
4. Choose model and generation mode to fit the task. With valid access the model list is loaded from the provider; alternatively you enter a model name freely. The generation mode can be selected: automatic as the recommendation, deterministic, or reasoning in levels. Higher levels deliver more considered content and take longer.
5. Set the default instruction. An instruction can be stored per team and is prepended to every request – up to 5,000 characters, freely editable, with a supplied template as a starting point. This is where tone, language and the rules that apply in your organization belong.
6. Log the use and analyze it. The AI activity log records every call, successful or failed, with time, status, person, function, model, provider, duration, attempts, token consumption and error message. The question of actual use is then an analysis and not an estimate.
What model-agnostic does not mean
It does not mean that every model delivers equally usable drafts. Which model suits your texts shows up in your content, not in a table. It also does not mean that the duty to review is taken off your hands – on the contrary, you take on the choice, the contract and the documentation yourself. It means that choice and responsibility sit in the same place: with the controller, where they legally sit anyway.
Before and after in direct comparison
| Criterion | Bundled AI | Your own provider |
|---|---|---|
| Choice of provider | The vendor decides | You decide and record the reasons |
| Contract and processing | Sub-processor in the contract of the vendor | Your own contract with the provider |
| Third-country transfer | Predetermined, not negotiable | Your own review, your own decision |
| Change of model | Happens without consultation | The model stays until you change it |
| Self-hosting | Cannot be connected | Your own compatible endpoint possible |
| API key | Sits with the vendor | Your key, encrypted and masked |
| Evidence of calls | Not visible | A log per call with model and provider |
| Ability to switch off | All or nothing | Per team, functions stay optional |
In practice
What this looks like in preeco
Three building blocks carry the process described above – in the products with AI functions.
Set provider, model and instruction
You choose OpenAI, Langdock or your own OpenAI-compatible endpoint. With valid access the model list is loaded from the provider, the generation mode can be selected, and a default instruction can be stored per team. On saving, a connection test runs against the configured model.
Your own endpoint, your own infrastructure
A self-hosted, OpenAI-compatible model can be entered as the provider. In the Private Cloud and On-Premises variants the content then does not leave your own infrastructure – the precondition for organizations that have to rule out transmission to external services.
AI activity log
Every call is logged, successful or failed, including the connection test on saving: time, status, person, function, model, provider, duration, attempts, token consumption and error message. That makes the use analyzable and demonstrable to auditors.
What the switch means in practice
The honest part first: your own provider is more work than the included one. You need an account with the provider, a data processing agreement, a decision about the place of processing and an entry in your list of service providers. Depending on the legal department that is a few days of lead time, and the smaller part of it goes to the technology.
Technically, by contrast, the switch is unspectacular. Select the provider, enter the endpoint and the API key, set model and generation mode, review the default instruction – the connection test on saving says immediately whether the access works. Existing documents stay unchanged; the AI produces drafts, it does not manage content.
The trade is worth it because afterwards nobody decides for you any more. You can change the provider without changing the software. You can run a model in your own organization. You can put a contract that carries your name in front of a vendor review. And you can demonstrate how the feature was actually used instead of assuring it.
Three mistakes when choosing a provider
Choosing the provider by the model name. What matters is the place of processing, the contractual position and the assurance about training with transmitted data. Which model delivers the better drafts is settled by a test with your own content, not by a recommendation.
Deferring the documentation. The access is set up in ten minutes, the entry in the records of processing activities takes longer. If it is deferred, it is missing exactly when the first review arrives.
Setting up the access once and never looking at it again. Keys expire, models are discontinued, teams change their instruction. A look at the log belongs in the same cycle as the rest of the vendor review.
How to tell that you need your own provider
- A group policy prescribes a particular AI provider or prohibits another.
- The content that would be transmitted must not leave the EU.
- Your organization already runs a model of its own that is meant to be used.
- The vendor review requires a contract in which your organization is a contracting party.
- The use of the AI has to be analyzable, for an internal audit or an approval, for instance.
If none of that applies, the convenient variant is defensible. If one of them applies, it no longer is.
FAQ
Frequently asked questions about choosing an AI provider
No – neither the model nor the access. preeco does not operate an AI service and is not a contracting party of the provider. You choose the provider, store your own API key and sign the contract including the data processing agreement yourself. The software supplies the interface, the logging and the settings.
No. The AI functions are optional throughout; every task can be completed entirely manually. In preeco | whistleblower they are deactivated on delivery and are activated only by administrators, per team. Without activation no AI elements appear in the interface.
Yes. Provider and model are settings and can be changed at any time. With valid access the model list is loaded from the provider, alternatively you enter a model name freely; on saving, a connection test checks the new setting. Which model was addressed and when is recorded in the AI activity log.
OpenAI, Langdock and any provider with an OpenAI-compatible interface through a freely chosen endpoint address. That includes a self-hosted model. In the Private Cloud and On-Premises hosting variants the content then does not leave your own infrastructure.
Through the AI activity log. It records every call with time, status, person, function, model, provider, duration, attempts, token consumption and error message – including failed calls and the connection test on saving. Together with your own contract and the entry in the records of processing activities, the transmission is thereby demonstrable.
Set up your AI provider together
Bring your requirements with you – place of processing, group requirement, your own model operation. In 30 minutes we will go through the choice of provider, the access and the logging.