Frequently asked questions about AI agents, automation and AI governance.
Answers to the questions that management, IT, data protection and business units ask most often before an AI project. As of September 2026.
What DENQ does
What does DENQ do?
DENQ is an implementation partner for AI agents and automation in Germany, Austria and Switzerland. We analyse workflows, decide for each process step between a fixed rule, automation and an AI agent, and implement the solution in existing systems with permissions, approvals and logging. We steer day-to-day operation together with the client using KPIs.
How does DENQ differ from an AI agency?
We only recommend an AI agent when a process requires one. Before that, we check every process against five criteria: repetition and volume, need for judgement, available data, clear ownership and risk profile. Where fixed rules are enough, we use conventional automation. Governance, data protection and the involvement of employee representatives are part of the project from the first draft.
Which countries does DENQ work in?
DENQ works for companies in Germany, Austria and Switzerland.
How does a project work?
A project starts with the AI Operating Review, a two to three week assessment. This is followed by implementation of the prioritised use cases with approvals, the transition to day-to-day operation with an Agent Board and KPIs, and finally scaling to further use cases with a gradual handover to the client's organisation.
AI agents in the company
What is an AI agent in a company?
An AI agent is a software system that uses a language model to evaluate information, prepare decisions and carry out actions in other systems, such as updating a record in the CRM. Unlike fixed automation, it can handle ambiguous input. That is why every agent needs defined permissions, approvals and a responsible person.
When does a process not need an AI agent?
An AI agent is not needed when fixed if-then rules without discretion are sufficient, when data is only transferred between two systems, when reports are produced without interpretation of their content, or when form and approval workflows follow fixed paths. In these cases, conventional automation is more reliable and more economical.
Which tasks are AI agents suited to?
AI agents are suited to five recurring work patterns: gathering and preparing information, checking and reconciling details, creating drafts, classifying and routing incoming cases, and monitoring and escalating deviations. Examples include draft quotes in sales, matching incoming invoices against purchase orders and pre-qualifying service requests.
Can AI agents be connected to existing systems?
Yes. AI agents are connected via interfaces to existing systems such as CRM, ERP, ticketing, email and document repositories. Which systems and data sources an agent may read or change is defined and documented for each agent.
What happens if an AI agent makes a mistake?
For every failure case, how the agent responds is defined before go-live. If data is missing, it asks for clarification or hands over to a person. If an interface fails, it retries a limited number of times and then reports the issue. If a result is uncertain, it flags the case as an exception for human approval. All actions are logged completely and traceably.
Governance, data protection and security
What is an Agent Board?
An Agent Board is a cross-functional body made up of management, process owners, IT, information security, data protection and employee representatives. It decides on the approval of use cases, the permissions per agent, the autonomy level, and on the expansion, adjustment or decommissioning of a solution.
What are autonomy levels?
Autonomy levels define how independently an AI agent may act. Level 1 (Assist): the agent analyses and recommends, the human decides. Level 2 (Prepare): the agent creates drafts, the human reviews and approves. Level 3 (Execute after approval): the agent implements after confirmation. Level 4 (Autonomous execution): the agent acts within defined limits, the human carries out spot checks. The Agent Board decides on each higher level based on KPIs.
How are data protection and the EU AI Act taken into account?
Data protection, information security and legal are involved from the first architecture draft. For each agent, we document data flows, data classification, permissions, and retention and deletion periods. The legal assessment, including under the EU AI Act and GDPR, is carried out by the client's legal department or external legal counsel. We provide the technical and organisational basis for it.
What permissions does an AI agent receive?
Each agent receives only the permissions its task requires (principle of least privilege). Read, write and execute rights are granted and documented separately for each system. Critical actions require approval by a human.
Getting started and working together
What is the AI Operating Review?
The AI Operating Review is DENQ's entry engagement and takes two to three weeks. The results are a prioritised use case portfolio, business cases, an assessment of existing AI initiatives, a governance framework and an implementation recommendation. The results belong to the client, even if they implement with another partner.
How do I find out where my company stands in its use of AI?
The free AI Readiness Check asks 13 questions on target state, processes and data, governance, organisation and measurement. It takes about four minutes and gives you a rating and a concrete first step for the area with the greatest need to catch up.
Your question is not listed?
In the initial call, we clarify your starting point and answer questions about your specific project.