AI Knowledge
What is a Corporate LLM? The difference from ChatGPT Enterprise
What makes a Corporate LLM, how it differs from ChatGPT Enterprise, Copilot and self-hosting, and the 5 questions to ask before you choose.
Four in ten German companies expect shadow AI: employees using generative AI nobody approved (Bitkom, 21 October 2025). Respond with a ban and you make it measurably worse. The number behind that is coming, and it genuinely surprised me.
First though, the term that has been drifting through tenders for two years without anyone defining it.
What a Corporate LLM is
A Corporate LLM is not a model architecture of its own but an operating model: a platform that provides one or several language models under a shared access, accountability and contract layer. The category is defined not by the model, but by the layer around it.
Picture a 50-person tax firm in Munich. Client data on US servers is off limits, and the partners have put that in writing. Yet three junior staff feed ChatGPT output into client emails every day, and nobody can demonstrate which data left the building. At that point the question is no longer whether AI is in use. It is who is accountable for it.
A language model answers requests. A Corporate LLM governs who may make which request, which data it reaches, and who can reconstruct that afterwards. Five characteristics form the core: tenant separation, roles and permissions including single sign-on, logging, a connected knowledge base, and a data processing agreement under Article 28 GDPR.
The number that settles the argument about bans
41 percent of companies with 20 or more employees use AI (Bitkom, 11 March 2026), but only 26 percent give their teams official access (Bitkom, 21 October 2025). Shadow AI grows in the gap between those two numbers.
Now the part that surprises most people. Where generative AI is banned, 67 percent of employees upload company data to public AI tools anyway. Where there is no policy at all, it is 33 percent (Gillespie et al., KPMG and University of Melbourne, 2025, 48,340 respondents across 47 countries).
So a ban does not halve unwanted usage. It doubles it. What you lose with a ban is not the usage, only your view of it. A Corporate LLM therefore does not solve a model problem, it solves an accountability problem: it makes the approved path more convenient than the covert one.
Corporate LLM, ChatGPT Enterprise, Copilot or self-hosting
The honest answer first, even though it does not help my own product: the boundaries do not run where vendors would like them to. Neither OpenAI nor Microsoft trains on customer data, both offer a data processing agreement, both have EU options. Anyone telling you otherwise is selling fear instead of substance.
The differences are finer:
| Criterion | ChatGPT Enterprise | Microsoft 365 Copilot | Self-hosting | Corporate LLM |
|---|---|---|---|---|
| Model choice | one provider’s models | OpenAI and Anthropic, admin decides | free, but self-operated | several providers under one layer: GPT-5, Claude Opus, Gemini Pro, Mistral Large |
| Training on customer data | no | no | no | no |
| EU processing | EEA data residency available, for new enterprise customers | EU Data Boundary, with exceptions | fully self-determined | depends on provider, verifiable |
| Data processing agreement | yes, via OpenAI Ireland Ltd. | yes | not applicable, processing is your own | yes |
| Operating effort | low | low | high | low |
Two details decide more in practice than any feature list, and both sit in the fine print.
With Microsoft 365 Copilot, so-called flex routing allows model processing to leave the EU at peak load, for example to the United States, Canada or Australia. For eligible tenants created after 25 March 2026, the feature is on by default. Administrators can switch it off. The models provided by Anthropic are excluded from the EU Data Boundary.
With ChatGPT Enterprise, EU data residency applies to new enterprise customers, and processing in the region requires inference residency to be enabled separately. OpenAI also notes that processing outside the GPU may still take place globally, and that authentication, routing and analytics leave the chosen region (OpenAI, Enterprise privacy).
Neither is a scandal. They are operating details that belong in your data protection impact assessment. Discovering them during the audit is a problem.
Why the category looks different in Germany
The German market makes three demands that rarely appear in Californian product plans. If one of these three applies to you, the benchmark debate is secondary anyway.
You are bound by professional secrecy. For law firms, tax advisors and medical practices, a data processing agreement is not enough. Section 203 of the German Criminal Code requires that contributing persons, which includes IT service providers, be expressly bound to secrecy. For lawyers, Section 43e of the Federal Lawyers’ Act makes this concrete: where services are performed abroad, access is permissible only if the protection there is comparable to domestic protection. That is not a marketing argument for EU hosting, it is professional law.
You have a works council. Section 87(1) no. 6 of the Works Constitution Act applies as soon as a technical system is objectively suitable for monitoring conduct or performance. The Federal Labour Court looks solely at that suitability; an intention to monitor is irrelevant (Federal Labour Court, decision of 16 July 2024, 1 ABR 16/23). Usage statistics alone are enough. Section 80(3) BetrVG sharpens it further: it now names artificial intelligence explicitly, and bringing in an expert counts as necessary when assessing it. The works council no longer has to justify that.
The legal situation is slowing you down. 53 percent of companies name legal ambiguity as an obstacle, 48 percent name data protection. Among companies actually using AI, the data protection figure rises to 54 percent (Bitkom Research, “Künstliche Intelligenz in Deutschland”). The problem does not shrink through usage, it becomes more visible.
On the EU AI Act, an assessment against the trend: if you are an SME summarising texts or doing research, it changes little for you in 2026. The obligations for high-risk systems moved to December 2027. What stays relevant are the transparency obligations in Article 50 from August 2026 and the weakened AI literacy obligation in Article 4. The greater lever is and remains the GDPR.
Five questions for your tender
These five criteria separate a platform in this category from a chatbot with an enterprise sticker. Work through them in this order: if someone gets question 1 wrong, you can skip the other four.
- Model choice. Can you switch the model per task? Ask: which providers are available, and what happens if one of them doubles its prices?
- Place of processing. Where does inference run, not just storage? Ask: are there exceptions at peak load, and are they in the contract?
- Accountability. Can you show your data protection officer who processed which data and when? Ask: can an audit export be produced without raising a ticket?
- Permission model. Does the finance team see the personnel files? Ask: how are permissions separated per department, and who grants them?
- Contracts. Does the data processing agreement match the actual architecture? Ask: who is the contracting party, which subprocessors are listed, and how do you learn about changes?
Get a concrete answer to all five and you are dealing with a serious provider. Evasive answers are an answer in themselves.
When a Corporate LLM is the wrong answer
Not everyone needs this category, and I say that as someone who builds such a platform. Three cases argue against it.
Below ten people without regulated data, the administrative effort is out of proportion. An individual subscription and a clear rule are enough. If you use AI exclusively for public content, such as marketing copy with no customer reference, you are buying compliance you do not need. And if you do not have a single use case in production, do not procure a platform, finish one case first.
The category pays off when three things come together: several teams, data worth protecting, and an obligation to prove both. A 60-person mechanical engineering firm with design data and a works council qualifies. A five-person landing page studio does not.
Three questions I always get
Is Corporate LLM a product name or a category? A category. The term describes the operating model, not a particular product. That is exactly why the definition is worth having: it makes tenders comparable.
How much time does the works council process cost? That depends on your organisation. Plan it early, not after the selection. Section 80(3) BetrVG gives the council an expert with no burden of justification, and that appointment is rarely in the week that suits you.
We already use ChatGPT. Was that wasted? Quite the opposite. Hands-on experience is worth more than any concept, because you know what you actually use it for. The step is not a replacement but an extension: the same benefit, with roles, logs and a contract your data protection officer can sign.
How to verify the place of processing is covered in EU hosting and GDPR. Why model choice is more than a question of convenience is in Why one AI model is never enough. RelationFlow is a platform in this category: GPT-5, Claude Opus, Gemini Pro and Mistral Large under one layer, EU hosting, a data processing agreement under Article 28, and an audit trail you can export. To walk the five questions through a real system, book a demo or start with the templates.
Sources: Bitkom, “Beschäftigte nutzen vermehrt Schatten-KI”, press release of 21 October 2025 and the accompanying study report “Künstliche Intelligenz in Deutschland” (n=604 companies with 20 or more employees). Bitkom, “Digitalisierung der Wirtschaft”, press release of 11 March 2026. Gillespie, Lockey, Ward, Macdade and Hassed (2025): “Trust, attitudes and use of artificial intelligence: A global study 2025”, University of Melbourne and KPMG, fieldwork November 2024 to January 2025. OpenAI, “Enterprise privacy” and “Data residency and inference residency for ChatGPT”. Microsoft Learn, “Data, Privacy, and Security for Microsoft 365 Copilot” and “Flex routing (EU and EFTA)”. Federal Labour Court, decision of 16 July 2024, 1 ABR 16/23.