Back to Blog

AI Managed Legacy Service

Expert interview: Modernising legacy systems with AI

How to modernise legacy systems using artificial intelligence. Why the retrofit approach makes your IT compliant.

Sebastian Grundhöfer, an expert in modernising critical IT infrastructures at 7P, discusses the challenges of modernising legacy systems using AI. Anyone who understands a legacy system has not yet modernised it. However, for the first time, decisions can be made on a sound basis. In the second part of our interview, Sebastian explains how 7P uses AI to guide the process from assessment to implementation, and how ‘Legacy Retrofit’ differs from a classic rewrite.

To the first part of the interview

Product concept ‘Legacy Retrofit’ instead of new build

Question: ‘Legacy Retrofit’ is a term that you at 7P actively coined. What is behind it?

Sebastian Grundhöfer: We don’t modernise everything as a matter of principle. Instead, we make an existing system ready and able to connect to new requirements. A new build may seem like the simplest solution at first, but it is highly risky in practice. It is associated with high costs and long project lead times. Additionally, the loss of deeply buried, undocumented specialist knowledge is often overlooked when opting for a complete new build. Retrofit, on the other hand, specifically looks for minimally invasive intervention points. We determine precisely which system components are critical and where future adjustments are blocked. At the same time, we assess the effectiveness of existing interfaces and test structures. Based on this information, we provide clear recommendations on where encapsulation, modernisation or replacement should take place.

Question: Who is ‘Legacy Retrofit’ for, and what does a typical customer look like?

Sebastian Grundhöfer: We encounter the typical customer profile wherever IT forms the backbone of core processes. This includes highly regulated markets, the manufacturing industry and the public sector. In these organisations, systems have often been running extremely reliably for years, but they have become sluggish and difficult to change over time. The system is highly relevant to the organisation’s specific needs, but the technology is outdated. If the remaining knowledge is held by a few key individuals only, every planned innovation becomes a real challenge. Pressure to act generally arises from external factors. For example, new requirements from the cloud strategy or stricter security and regulatory requirements simply cannot be implemented flexibly with the existing infrastructure.

Question: How does such a project work in practice?

Sebastian Grundhöfer: We divide the process into three clear phases: analysis, piloting, and implementation. During the analysis phase, we use the Fast Check to create complete transparency. We scrutinise the system architecture and make concrete dependencies and operational risks visible. In the second phase, we develop a robust foundation for decision-making. To achieve this, we determine the most economical option for each system component, be it encapsulation, refactoring, migration or continued operation and compare the respective costs. In the third phase, we then implement a controlled pilot. A clearly defined area is modernised to validate the procedure, tooling and governance in live operation, before scaling up the model.

AI in implementation and the “black box” problem

Question: What prerequisites must companies have in order to be able to use AI-supported modernisation at all?

Sebastian Grundhöfer: From a technical point of view, they need secure access to all relevant artefacts. This includes source code, build processes, data models, and interface documentation. Many organisations underestimate how widely these building blocks are distributed within the company. In addition, a protected environment is required, since sensitive business logic must never be fed into public AI tools. Last but not least, it is crucial to have a realistic set of expectations: AI can help to structure a system much more quickly. However, it cannot transform a poorly maintained system into a modern product overnight.

Question: In which phases of implementation does AI play the biggest role today, and where do you see its potential for the future?

Sebastian Grundhöfer: We currently see the greatest leverage in analysis and quality assurance. Quality assurance involves the automated generation of tests to ensure the old system continues to function correctly. This is essential for safe modernisation. Over the next two years, I anticipate the greatest potential lies in agent-based workflows. Specialised AI agents will prepare sub-tasks such as code refactoring or creating documentation drafts independently. However, the motto ‘human in the loop’ still applies.

Question: How do you deal with the ‘black box’ problem of AI? Will decisions remain traceable and auditable?

Sebastian Grundhöfer: ‘Never treat AI as the final decision-making authority.’ AI makes suggestions and prepares work, but every final decision is documented and remains traceable. In regulated industries, a plausible-sounding result is not enough. It must be fully verifiable too. This is why all AI results are versioned, validated, and double-checked by our experts. This is the only way to ensure that the entire process remains auditable.

Question: Are there any clear limits to when it would be better not to use AI?

Sebastian Grundhöfer: Yes, very clearly. I would avoid using AI in situations involving highly sensitive data or where a technical review of the results is not possible. I also advise caution when making productive changes to critical systems. AI-generated code must undergo the same rigorous quality and security checks as code written by humans. In critical contexts, AI should only have a supporting role and must never make decisions independently.

Regulatory and digital sovereignty

Question: With DORA, NIS2 and BAIT, regulatory pressure is increasing. Are regulations more of a driver or a brake?

Sebastian Grundhöfer: Both. It acts as a brake when companies only view it as a tiresome documentation obligation. However, when understood correctly, it becomes a powerful accelerator. The regulations force companies to thoroughly question the resilience of their systems, as well as disclosing their personnel and technological dependencies. In essence, the regulations address classic modernisation issues and highlight long-standing technical problems.

Question: How can you ensure that AI-supported approaches do not compromise these strict requirements? What role does digital sovereignty play in this?

Sebastian Grundhöfer: For us, it’s a controlled engineering process involving isolated data rooms and clear review concepts. In practical terms, digital sovereignty means that we always retain full control over where our code is located and which models are used. Critical systems concern core logics and security architectures. These cannot simply be outsourced to global platforms without careful consideration. For European companies, data protection must form an integral part of IT architecture.

Outlook and personal advice

Question: What are the concrete business benefits for customers, and what results can they realistically expect?

Sebastian Grundhöfer: The business case is primarily measured by two factors: risk minimisation and regained development speed. However, the greatest added value lies in the ability to make well-founded decisions. Rather than acting on instinct or under political pressure, as was the case in the past, fact-based analyses provide clarity on where encapsulation is sufficient and where targeted migration is necessary. When it comes to costs, I am deliberately cautious about making sweeping promises. However, AI demonstrably saves time in the analysis and preparation phase. The real economic leverage lies in preventing costly mistakes later in the project. This is why we never start with an untested major investment; first, we establish a reliable diagnosis and test the procedure step by step on a defined pilot before implementation.

Question: Where will companies be in five years’ time, and what will distinguish the successful ones from the rest?

Sebastian Grundhöfer: I believe that we will see a clear difference in the next five years. The successful companies will not necessarily have completely decommissioned their legacy systems. However, they will have examined them closely, documented them properly and integrated them into a modern architecture. They will know exactly which parts are critical and how to implement changes in a controlled manner. The others will continue to operate systems that are functional, but prevent any urgent changes from being made.

Question: Is there anything you have never been asked in this discussion but would absolutely like to say?

Sebastian Grundhöfer: Definitely. When it comes to legacy, we talk too much about technology and not enough about responsibility. Many of these systems have been running stably for years because they were originally designed to solve a specific problem very effectively. However, over time, the environment changes while the system remains unchanged. Legacy systems have enormous specialist value. This is not a matter of disparaging everything that has been done so far. Rather, the existing value must be secured and the system modernised to ensure continued efficiency.

Question: What is your concluding, personal advice to a CIO or CDO who has to start modernising tomorrow?

Sebastian Grundhöfer: Don’t start with a major rewrite. My advice is to start with transparency. Choose a business-critical system where there is a high level of pressure to change. Obtain a reliable external perspective on the areas of architecture, risk, testing and security. Make your decisions based on these facts. Be sure to involve the people who know the system today, too. This may sound obvious, but it is often overlooked in practice.

In the first part of the interview, Sebastian discusses why transparency must precede every modernisation step and explains how the ‘Legacy Fast Check’ helps with this.

Consent settings

This website only loads content from other providers once you agree. Here you can change or withdraw your choice for each service; it is only stored in your browser. More in our privacy policy.

External media