AI is no longer just a “tool”; it increasingly influences hiring, credit decisions, customer support, security and marketing. The EU AI Act introduces a framework of obligations and responsibilities for entities that develop, market or use AI systems. Those who prepare in time reduce regulatory risk and can more easily introduce AI into their processes.
Who is subject?
In practice, business entities are most often in the role of:
- deployer (user of AI systems) – uses AI in business processes
- provider (developer/brand owner of AI) – develops or puts AI on the market under their own name
- or participant in the supply chain (integrators, distributors).
Risk classification: a key question
The obligations depend on the risk level of the AI system. Particularly sensitive are high‑risk systems (e.g., in certain areas of recruitment, education, healthcare, critical infrastructure). In practice the first step is to inventory AI tools and assess whether they fall into risk categories.
Governance: who “owns” AI?
Good AI compliance is not reduced to a single document. Best practice is to:
- appoint responsible persons (legal, IT/security, HR, product)
- set rules for procurement and approval of AI tools
- introduce a registry of AI systems and their purposes.
Documentation and auditability (audit trail)
Regulatory risk often arises when a business entity cannot prove:
- why a tool was introduced
- what data it uses; how quality and bias are controlled
- who oversees the outputs of AI (human oversight).
AI and GDPR: overlaps that are often overlooked
If AI processes personal data, GDPR obligations remain: legal basis, transparency, minimisation, retention periods, security and data subject rights. A particularly important question is automated decision‑making and profiling.
Practical preparation steps
- List AI tools (including hidden ones in SaaS).
- Define their purposes and assess the risk level.
- Introduce an internal procedure for AI approval and vendor due diligence.
- Align contracts with suppliers (security, sub‑processors, data transfers).
- Update privacy notices and internal policies.
- Provide training for teams (HR, product, sales).