EU AI Act – Preparations on the user side
The European Union’s horizontal regulation on the use of artificial intelligence—the EU AI Act—imposes specific obligations not only on developers of AI tools but also on organizations that use various AI systems. The regulation is based on a risk-based approach, so the extent of each requirement depends on the nature of the use and the level of risk.
Since the provisions apply throughout the entire lifecycle of the systems in question, compliance cannot be achieved in a single step: it requires continuous review and management.
Recurring tasks in practice
Risk classification and documentation. The assessment of risk for each specific use case is not tied to the technology itself, but rather to its intended purpose. The same tool may fall into one category if it is used to prepare summaries, and into another if, for example, it supports decisions related to employment. From the employer’s perspective, therefore, the first question is what purposes employees use each AI system for—as this determines exactly which regulations the employer must comply with.
In the case of high-risk uses, the employer must be able to demonstrate compliance with its obligations if contacted by regulatory authorities. One tool for this is logging: the regulation requires operators of high-risk systems to retain automatically generated logs. In practice, this makes it possible to trace AI usage and system-level decisions retrospectively—both for investigating incidents and for demonstrating compliance. Although the regulation does not explicitly stipulate such requirements for lower risk levels, organizations can only be certain that specific uses truly fall into the lower risk category if they are consciously and regularly reviewed.
Review. To ensure that the risk assessment of each use case reflects actual operations, it is necessary to review them at regular intervals. In addition to ad hoc reviews triggered by changes, scheduled reviews are therefore also warranted: this ensures that emerging new practices are incorporated into the compliance process.
Human oversight and training. The EU AI Act mandates human oversight as a specific requirement for high-risk use cases and, in certain instances, also requires that AI-generated content be appropriately labeled. However, verifying outputs is not merely a regulatory issue: language models can generate content that is convincingly phrased yet inaccurate, so human review is a fundamental requirement for responsible use, regardless of risk classification. All of this, however, requires adequate user training. Employees must know when and what to check, and they must be aware of the technology’s limitations. The regulation also reinforces this point: organizations using AI tools must ensure that their employees are proficient in AI.
From compliance to operational capability
Compliance with the EU AI Act is partly a legal requirement, but the path to achieving it also involves establishing an operational framework that can be valuable to the organization even beyond regulatory requirements. To meet compliance criteria, it is first and foremost essential for the organization to have a unified view of the AI tools used by its employees. Everything else builds on this: logged operations, human oversight, and lifecycle management. The steps toward preparedness are therefore not isolated legal tasks; they also involve building organizational capabilities that support the development of a culture of responsible, transparent, and effective AI use.
In our summer series, we explored the most important challenges of corporate AI use: issues of visibility, resource management, data protection, and regulatory compliance. We’ll continue to cover this topic—be sure to follow us.


