AI rollout plan: bringing a private AI assistant to 1,000 employees in waves
Eurokommerz, Vienna, since 2006: Private AI/ML · IT Managed Services · Enterprise Training · AI Hardware & Software
- Roll out in waves by department: a pilot group first, then departments whose use cases, document collections and data owners are ready, each opened only when the previous wave passes an agreed gate
- Grant access through groups in the directory service that the front end reads at sign-in; in Open WebUI, models and knowledge bases are shared per group and permissions only add up, so keep the defaults minimal
- Make policy acknowledgement and training a condition of the group membership; Article 4 of the AI Act, as amended in July 2026, asks for measures to support AI literacy, and the Commission’s Q&A says no certificate is needed and an internal record can be kept
- Run a support category with three routes from the first day (access, platform, content) and a feedback loop in which thumbs-down ratings and wrong-answer reports go to the owner of the collection
- Before each wave, track the active share, queries per active user and use cases completed per department, and check busy-hour requests in flight, queue and time to first token against the user count after the next wave
Eurokommerz × Vixen.UNO: Private AI/ML Talk to an expert →
How to roll out a private AI assistant to 1,000 employees
An AI rollout plan brings a private AI assistant to employees in waves by department: a pilot group first, then departments in an order set by how ready their use cases are, each opened only when the previous wave has passed an agreed gate. Every wave brings its own use cases and document collections, gets access through a group in the directory service, accepts the usage policy and completes training before its first sign-in. A support channel and a feedback loop run from the first day, and a capacity check on the measured load decides whether the servers can carry the next wave. For 1,000 employees, four waves of growing size make a workable plan, as in this example.
| WAVE | WHO | PREREQUISITES | GATE TO NEXT WAVE |
|---|---|---|---|
| 0, pilot | 40 users from two teams | single sign-on, usage policy, query log, pilot metrics agreed | pilot metrics met on the teams’ own questions |
| 1 | 150 users, two departments | collections indexed with access rights, champions named, training module ready | 6 in 10 users active within 30 days, wrong-answer reports closed |
| 2 | 350 users, three departments | capacity check passed, service desk category live | busy-hour queue and time to first token within target |
| 3 | 460 users, rest of the company | second server for failover, policy in onboarding for new staff | active share and ticket volume stable over one review |
An example plan for 1,000 employees; group sizes and thresholds are ours and are replaced by your own.
Planning the waves by department and use case
A department is ready for a wave when it can name two or three recurring tasks for the assistant, point to the document collections that answer them and name a data owner who decides who may read each collection. Customer service with a product knowledge base, IT operations with runbooks and legal with a template library are typical early candidates, because their documents already sit in shared repositories.
Keep uses that touch the purposes in Annex III, point 4 of the AI Act out of the general waves. That point covers employment and workers’ management, including systems intended “to analyse and filter job applications, and to evaluate candidates” and systems used to monitor and evaluate the performance and behaviour of workers. Such a use needs a separate decision, and its classification is a legal assessment for the company’s legal department.
Wave 0 has two jobs: to prove one process with measured results and to produce the load figures that size the servers for the company. Our article on what to measure in a private AI pilot covers both.
Our Private AI/ML service starts with a pilot on one process with clear metrics and scales only what has proved its value. Tell us which departments you would put in the first two waves and the tasks they would bring.
Access groups from the directory service
Access follows groups in the directory service, so a wave goes live when its department groups are added to the group that the identity provider admits to the assistant, and no account is created by hand. A clear structure has one group per department or wave that may sign in, one group per use case that needs a restricted collection or model, and one group for platform administrators.
The identity provider sends memberships as a claim in the sign-in token. With ENABLE_OAUTH_GROUP_MANAGEMENT set, Open WebUI matches its groups to that claim at each sign-in and removes users from groups the claim does not list, including groups assigned by hand, with no exemption for administrators. ENABLE_OAUTH_GROUP_CREATION creates groups that do not exist yet. A user who is signed in sees a change of membership only after signing out and in again. Models and knowledge bases set to private or restricted are shared with chosen groups or users, with read access to use them and write access to change them. The documentation states that permissions are additive and that deny rules do not exist, so a member of several groups receives all their grants. Keep the default permissions minimal and grant features per group.
Our guide to a private ChatGPT alternative covers the sign-in side in detail, from OpenID Connect and SAML to token lifetime and SCIM deprovisioning.
Usage policy acknowledgement and training before access
Tie the group membership to two records: the person has accepted the current version of the usage policy and has completed the training module for their role. The policy names the data classes allowed, the tasks excluded and what the query log holds. Our guide to shadow AI policy and controls has an example matrix of data classes. When the learning platform or HR system confirms both records before the directory adds the person to the group, the list of trained people and the list of users match.
Article 4 of the AI Act, as amended by Regulation (EU) 2026/1744, the Digital Omnibus on AI, in force since 27 July 2026, requires providers and deployers of AI systems to “take measures to support the development of AI literacy” of their staff and of other persons who operate or use AI systems on their behalf. The Commission’s AI literacy Q&A, last updated on 27 July 2026, says “There is no need for a certificate” and that organisations “can keep an internal record of trainings and/or other guiding initiatives”. It also warns that in many cases relying on the instructions for use, or asking staff to read them, “might be ineffective”.
Our guide to AI literacy training under Article 4 sets out the content per role. For a rollout, plan one live session per department, held on the production assistant with the department’s own use cases, a recorded version for staff who join later and a repeat when the model or a collection changes.
Support channel and feedback loop
Open an AI assistant category in the service desk before wave 1 and route tickets by type. Access problems, such as a missing group or a failed sign-in, stay with the service desk. Platform problems, such as errors or slow answers, go to the platform team. Content problems, meaning wrong, outdated or missing answers, go to the data owner of the collection, who corrects the source document or the collection. The platform team then adds the question and the corrected answer to the evaluation set, so that a later model change is tested against it.
A champion in each team answers colleagues’ first questions and collects examples of good and bad answers. In Open WebUI, users rate answers with “thumbs up or thumbs down” and can add topic tags, and where several models are offered, administrators see a leaderboard in which they are “ranked using an Elo rating system”. Each rating stores a snapshot of the conversation, so the thumbs-down list is where the content review starts.
NIST’s AI Risk Management Framework 1.0 (NIST AI 100-1, January 2023) describes the same loop. Its MEASURE 3.3 subcategory calls for “Feedback processes for end users and impacted communities to report problems and appeal system outcomes”, and MANAGE 4.3 states that “Incidents and errors are communicated to relevant AI actors”. Tell users what changed after their reports: Open WebUI lets administrators display banners “on the new-chat screen”, shown while no chat is open and set in the admin panel or through WEBUI_BANNERS.
Adoption metrics: active users, queries per user and use cases completed
Measure adoption per department, against the headcount with access, and review the figures at each gate.
| METRIC | DEFINITION | SOURCE | WHAT IT DECIDES |
|---|---|---|---|
| Active share | users with a chat in 30 days, divided by group size | front end analytics, directory | fit of training and use cases |
| Queries per active user | answers per active user in 30 days | analytics filtered by group | depth of use after launch |
| Use cases completed | agreed use cases whose acceptance check passed | wave plan, evaluation set | whether the department is done |
| Thumbs-down share | down ratings among all rated answers | ratings in the admin section | order of the content review |
| Support tickets | tickets per 100 users, by route | service desk | readiness for the next wave |
Our summary; analytics fields as described in the Open WebUI documentation, read on 10 October 2026.
Open WebUI’s analytics dashboard, open only to administrators under Settings, Admin, Analytics, shows messages, tokens, chats and users, broken down by model and by user, and filters by time period and user group. It counts assistant responses, and deleting a chat or a user removes its messages from the figures. The user table shows the 50 users with the most messages in the period, so the active share of a department with several hundred users needs the analytics API with a higher limit. Active share and queries show use; use cases completed show whether the department received the tasks it was promised, and high use with no completed use case calls for a review of the collections.
The dashboard shows activity per user, which is personal data. Report by department, and agree the level of detail with your data protection officer before the first report. If the decision is to switch the dashboard off, ENABLE_ADMIN_ANALYTICS set to False hides it after a restart.
Capacity check before the next wave
Take the busy hour of the current waves from the serving engine’s metrics. In vLLM these are the requests in flight (vllm:num_requests_running), the queue (vllm:num_requests_waiting) and the share of KV cache blocks in use (vllm:kv_cache_usage_perc), all gauges, and time to first token, a histogram (vllm:time_) read at the 95th percentile. Scale the busy-hour peak to the number of users the platform will have after the next wave. If, as an example, 190 users produce a peak of 12 requests in flight, the same ratio predicts about 34 for the 540 users after wave 2.
Correct the ratio for the next wave’s use cases, because a department that works with long contracts sends longer prompts than one asking short questions. The wave opens when the forecast peak fits the KV cache with the headroom you have set and the time to first token stays within target. If it does not fit, the wave waits for the next server, so that decision has to be made early. Our guide to GPU capacity planning for an LLM platform sets out thresholds, headroom and the review procedure.
Our Private AI/ML service includes the selection and supply of GPU servers, from a single server to a cluster. Send us the busy-hour figures of your last wave and the headcount of the next one through the form below.
Communication, change management and employee representatives
Announce each wave to the department before the training date, jointly from the department head and IT. The message states what the assistant does for the department, which data may go in, what the query log records and where to get help. After each wave, publish the use cases completed and the fixes made from user reports.
Where the company has a works council or other employee representatives, national law may require information or consultation before an assistant with a query log goes live; Directive 2002/14/EC sets the EU framework and names “decisions likely to lead to substantial changes in work organisation” among its subjects, and whether it applies is a legal assessment for the company’s legal department.
Rollout steps from pilot to company
- Agree the use cases, the metrics and the gate of the pilot, and run wave 0 with one process.
- Write the usage policy and the training module per role, and set up the record of both.
- Create the directory groups per department and use case, and map them to models and collections in the front end.
- Open the support category with its three routes, and name a champion in each team.
- Train the department, confirm both records and add its group to the assistant’s access group.
- Review the adoption metrics, ratings and tickets per department at each checkpoint.
- Run the capacity check against the user count after the next wave and its use cases.
- Open the next wave when its gate is met, and add the second server before the whole company depends on the assistant.
What we do
Our Private AI/ML service builds an AI platform under your control, on your servers or on dedicated hardware in a Tier-3 data centre in Lithuania, with a query log and data and permissions management, and assistants that respect each user’s access rights. We start with a pilot on one process with clear metrics, scale only what has proved its value, and we train your team to run the platform and develop it further. Eurokommerz holds the contract and supplies the GPU servers, from a single server to a cluster, with engineering by our partner Vixen.UNO and ongoing support under an agreed SLA. The first call is free of charge, and the price of the technical assessment is fixed before work begins. How we handle your data during the project is set out on our security and compliance page.
FAQ
What is an AI rollout plan?
How do you roll out an AI assistant to employees?
How do you measure internal AI assistant adoption?
Do employees need training before using an internal AI assistant?
Do we need to involve employee representatives in an AI rollout?
When should an AI assistant be opened to the next department?
Send us the number of employees, the departments and tasks you would put in the first waves, your identity provider and where the assistant should run. We reply within one business day, and after the first call you leave with 2 to 3 possible solution scenarios. The first call is free of charge.
Talk to an expertWe reply within one business day