Single entry point
One gateway to all models instead of direct integrations from each service - routing and vendor switching without reworking processes.
How to deploy Claude in mid-market and enterprise: from pilot to scale, where GDPR really blocks AI, where it does not, and what closes faster.
The question for 2026 is not whether to implement Claude, but how to move from pilot to scale. By 2026, AI has become mainstream: about 78% of organizations already use it in at least one business function. But according to the MIT NANDA report "The GenAI Divide" (2025), about 95% of enterprise generative AI pilots produce no measurable P&L impact, and only about 5% reach scale. The gap is not model quality, but how AI is embedded into processes and data.
This article covers three things that determine the outcome: where to start a pilot and how to grow it to scale; why GDPR is often applied more broadly than the law requires (commercial data is rarely personal, and a pilot can be built legally on anonymized and synthetic data); and which task level mid- and large-sized business can close fastest with Claude, based on real KT.Team cases.
AI adoption is already mainstream, and generative AI has reached about 67% penetration by market estimates. So the bottleneck has shifted: it is no longer "is there a suitable model" but "has the use case been turned into a working process." The MIT NANDA report calls this the GenAI Divide - the gap between a pilot and P&L impact. The same report offers a practical benchmark: buying from a specialized vendor or partnering reaches results in about 67% of cases, while in-house builds from scratch succeed three times less often, at roughly one third.
The probability is higher where adoption is driven by a line manager, not just IT. The takeaway for mid- and large-sized business: scale comes not from "one more model," but from a narrow process, a measurable result, and a business-side owner.
Claude (Anthropic) is positioned for enterprise around agents, coding, and complex multi-step workflows, not consumer chat.
Practical strengths of the lineup (Opus and Sonnet) for enterprise tasks: agentic work with tools, code generation and refactoring, long context for working with large documents, and extracting structured data from unstructured text.
Multi-vendor is the norm: a notable share of enterprises run several frontier models at once, and Anthropic is among the market leaders by share of enterprise spending on frontier LLMs.
This is an argument not for hard lock-in to one vendor, but for a single gateway router. In CIS, there is no direct access to Claude through the official API or cloud providers; the correct access path is through a gateway. At KT.Team this is LLM & Security Gateway: a single entry point to models with routing and a security boundary.
The first use case is chosen by three criteria at once, not by how "trendy" the topic is:
GDPR regulates not "any data" but personal data. Article 3 defines personal data as any information directly or indirectly relating to an identifiable natural person; the legal key is whether a specific person can be identified. Item master data and product attributes, product composition, technical specifications, tender terms, invoices, warehouse documents, industry classifiers, and aggregated metrics do not relate to a specific person, so the personal-data regime does not apply to them.
This leads to a common mistake: applying the law more broadly than required and blocking AI unnecessarily.
| Myth | What the law says | How to do it right |
|---|---|---|
| "All our data is personal, so we cannot use a foreign model" | Personal data is only information that identifies an individual (GDPR, Article 3). Commercial, aggregated, and anonymized data do not fall under this regime | First classify the process fields: which ones are actually personal data and which are not |
| "An AI pilot automatically means processing personal data" | If personal data never enter the boundary, the personal-data processing regime (consent, handling "raw" personal data) does not arise legally | Build the pilot on synthetic data, anonymized samples, or non-personal commercial data |
| "Removing full names from the export is enough" | Anonymization (Article 3, Clause 9) is a lawful mechanism within the law itself; from 2025-09-01, the updated anonymization procedure applies (233-FZ of 2024-08-08, supervised by Roskomnadzor) | Anonymize according to the established procedure, not by just cutting out a couple of fields; at scale, use a gateway with obfuscation |
When a process cannot work without real personal data, the responsible pattern is not to send personal data directly to someone else's model, including a foreign one. LLM & Security Gateway provides a two-way boundary: personal data is tokenized before the model and de-anonymized in the response - the provider sees only anonymized data, which also removes cross-border transfer risk. For local preparation of text before sending, there is the anonymize skill.
The fastest to adopt are tasks with a narrow process and measurable result; agents and the security boundary are already scale-level. The table goes from the fastest entry point to the most mature level, each with real KT.Team proof.
| Task level | What Claude does | KT.Team proof |
|---|---|---|
| 1. Classification and routing | Sorts requests, documents, and item masters by category and routes them onward | LLM classification for one of CIS's top 3 developers; product matching in AI-PIM Fix Price |
| 2. Data extraction from documents | OCR + LLM for source documents, invoices, specifications, and composition | Document processing in logistics; AI accountant OSNO-VA |
| 3. Support and internal assistants | Meeting notes, policy responses, employee support | AI meeting protocol; regulations assistant |
| 4. Analytics and evaluation | Evaluation of quality, tenders, procurement, and HR profiles | Quality control, tenders, procurement, HR assessment |
| 5. Coding environment (AI-SDLC) | Dev copilot and development agents - the fastest ROI in the market (~70% penetration) | AI-SDLC Fix Price; KT.Team's AI-native approach |
| 6. Agents and corporate memory | Multi-step scenarios with context preserved between steps | Sloy - corporate memory, Sloy case study; agent fleet management |
| 7. Security boundary | Single entry point, budgets, observability, personal data obfuscation - a separate level at scale | LLM & Security Gateway |
Most level 1-4 scenarios start well as a narrow pilot; levels 5-7 usually grow out of the first successful deployments.
At scale, the control point is not a single model, but the layer between processes and providers. What it covers:
One gateway to all models instead of direct integrations from each service - routing and vendor switching without reworking processes.
Spend limits by team and process, request logs and metrics - usage and quality are visible, not blurred into a subscription.
Two-way boundary: personal data is replaced with tokens before the model and restored in the response - the provider sees only anonymized data.
Multi-vendor is the norm here, not the exception: a single gateway lets you keep several frontier models and choose the right one for each task without locking into one provider. More - LLM & Security Gateway.
Launch a pilot in 2-4 weeks - a verifiable first step:
External sources are cited in the text.
A lawyer or DPO must confirm the exact classification of specific datasets and the requirements under GDPR; the legal wording here is a general principle, not a conclusion about your process. - MIT NANDA, report "The GenAI Divide" (2025), percentages based on summaries: fortune.com/2025/08/18/mit-report-95-percent-generative-ai-pilots-at-companies-failing-cfo/ -
Analysis of the MIT report (buy vs build, the role of line managers): legal.io/blog/5719519/MIT-Report-Finds-95-of-AI-Pilots-Fail-to-Deliver-ROI-Exposing-GenAI-Divide -
Enterprise LLM adoption statistics (market estimates of ~78% / ~67%, top use cases): index.dev/blog/llm-enterprise-adoption-statistics - Anthropic, Claude's enterprise positioning: anthropic.com/news/claude-opus-4-5