Chinese AI in German Firms: Why DeepSeek Barely Gets Used

Serverraum in einem modernen Unternehmen
Photo by Albert Stoynov on Unsplash

Chinese AI models regularly draw attention with low prices and strong benchmark results. So far, that competition has barely reached German companies. A new Bitkom survey of 603 companies with at least 20 employees found that, among firms already using AI, only 2 percent use DeepSeek and 1 percent use Alibaba’s Qwen. ChatGPT, by contrast, reaches 76 percent. Those figures are not a quality ranking of individual models. They do show how far the public performance debate can be from actual enterprise deployment.

That is precisely why the result deserves a closer look. Many model discussions treat selection as a simple comparison of price, context window, and benchmarks. For a company, it is also a procurement and control decision. Where does data run? Who processes prompts and attachments? What contracts, access controls, and audit evidence exist? Can a team operate a model in a controlled environment if needed? Those questions often decide the outcome before a single benchmark point does.

Key takeaways

  • In Bitkom’s survey, only 2 percent of AI-using German companies use DeepSeek and 1 percent use Qwen, while ChatGPT reaches 76 percent.
  • The survey measures use in companies with at least 20 employees, not the quality of every model or private use by individual workers.
  • Privacy, security, contract terms, and existing integrations usually matter more to companies than a low model price.
  • Open weights and local deployment can improve control, but they do not automatically solve operations, updates, safeguards, or liability.
  • A sound model strategy starts with the use case and the data, not with the loudest benchmark.

The figures measure use, not technical superiority

The Bitkom data need a careful reading. The survey covered 603 companies with at least 20 employees; its shares refer to organizations already using AI, and respondents could name more than one tool. It does not follow that 76 percent of all German companies use ChatGPT. Nor does it show that Chinese models perform worse. It describes a procurement reality: which applications are visible, approved, and integrated into organizational workflows?

That reality is changing quickly. The ifo Institute reported in May 2026 that 54.5 percent of companies in Germany use AI in business processes. Large companies were further ahead, but small and medium-sized firms had also caught up substantially. ZEW likewise finds that many firms deliberately provide generative AI applications to their staff. As adoption spreads, the pressure grows to define roles, data classes, and approvals rather than merely allowing some tool. A model’s origin is one criterion among several, but it is not a trivial one.

Why established platforms arrive first

The lead held by U.S. offerings is not explained by brand recognition alone. Large providers are often already present in an IT environment through office software, cloud contracts, identity management, and security functions. A procurement team can then build on existing data-processing agreements, centralized sign-on, logging, and support channels. That does not eliminate every risk, but it reduces the effort required to assess, buy, and, if necessary, turn off a service.

With a new model provider, companies must do that work from the beginning. They need reliable information about data flows, storage locations, subprocessors, deletion periods, and incident processes. Regulated sectors add requirements for documentation, authorization concepts, and separation of sensitive data. A low token price can still be economical if it offsets those follow-on costs, but it is not automatically economical. Bitkom’s figures therefore also point to friction in governance and procurement, not just a preference for one chatbot.

A blanket security judgment based on origin would nevertheless be too crude. A U.S. cloud model can be unsuitable for a confidential use case, while an openly available model operated in a secured European environment may be a sensible choice. Conversely, a locally run model does not guarantee privacy when access is too broad, logs are missing, or staff feed in data without controls. The decisive factor is the actual data path and operating model. Ignoring that distinction mistakes sovereignty for a label.

Open weights are an option, not a free pass

For some tasks, an openly available model can be attractive: internal knowledge search, classification, or drafts using a clearly bounded data set, for example. Run locally or through a European hosting partner, it can offer more control over data flows than a public consumer application. That can make sense for privacy, latency, or cost. It still requires technical capability. Models must be updated, permissions set carefully, inputs filtered, and outputs monitored. Vulnerabilities in the surrounding software do not disappear as a result.

The useful comparison is therefore rarely “China or the United States.” Better questions are: does the use case need a frontier model, or will a smaller specialized model do? Can it process personal data? May the system execute tools, or should it only summarize text? Is there a human approval before an external action? The recently reported debate about safety boundaries for capable agents shows why these are more than compliance exercises. As autonomy increases, the environment becomes as important as the model.

What companies can do now

Rather than naming one provider for the whole organization, teams should build a small model matrix. For each use case, it can record the data class, permitted models, hosting location, cost range, approvals, and a shutdown path. A public marketing text deserves different treatment from a customer contract; an ideation chat differs from an agent that can access tickets or source code. A limited pilot using anonymized or synthetic data yields more knowledge than uncontrolled shadow use.

Procurement also needs a realistic exit plan. Can a prompt archive be exported? Can access rights be revoked centrally? Are there reliable logs for troubleshooting and audits? Which parts of a workflow depend on proprietary interfaces? Those questions apply to every provider. They are especially useful for assessing open models on their merits instead of rejecting them reflexively for geopolitical reasons or adopting them blindly because of cost enthusiasm.

Outlook: selection is becoming an operating question

DeepSeek’s and Qwen’s low use is not an endpoint but a snapshot of a rapidly expanding practice. As models become cheaper, open weights more common, and hosting options more mature, the market can shift. The central task for German companies will remain the same: combine model performance with data control, operational security, and accountability. Organizations that establish those foundations can evaluate new providers faster and more soundly later, regardless of the country from which the next strong model arrives.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top