leuschner.ai

EU AI Act & the safe use of AI

TL;DR / Quick Answer

The EU AI Act has been in force since 1 August 2024 and sets new global standards for the regulation of artificial intelligence. For organizations, this means: AI literacy becomes mandatory. This guide translates the legal requirements into a practical work logic for everyday life.

Generative AI is already being used in many companies, associations and social organisations. Often regardless of whether it has been officially approved.

Employees use AI, for example, for spelling, translations, email drafts, summaries, research and ideas.

The benefit is obvious. A blanket ban therefore often fails to prevent its use. Instead, uncontrolled solutions emerge via private ChatGPT or Gemini accounts, private smartphones, personal email addresses or freely accessible translation services.

The real risk

With private AI accounts, the organisation loses control over entered data, contractual conditions, data protection, storage, deletion, traceability and access by former employees.

Translation services such as DeepL are also critical if internal, confidential or personal texts are entered without an appropriate company contract.

The problem is therefore rarely the use of AI itself. The problem is unregulated AI use without approval, without training and without traceable responsibility.

The better way

Many organisations do not need a large AI strategy at first. They need a secure basis:

  1. approved tools

  2. clear rules for company data

  3. understandable usage guidelines

  4. trained employees

  5. documented responsibilities

  6. regular review of new applications

Microsoft 365 Copilot Chat can be a useful starting point for many Microsoft 365 environments. When used with a business account, the protection mechanisms of the Microsoft 365 environment apply. Nevertheless, Copilot also does not replace clear rules, data classification or professional review of results.

GDPR and the EU AI Act

The GDPR also applies to AI use. Personal, confidential and business-critical data may only be processed within the permitted framework.

The EU AI Act also requires a responsible approach to AI. A central element is the AI literacy of the people who use AI systems. They must understand which tools are allowed, which data may be entered, where AI can make mistakes and when human review is required.

What matters is: this is not about an arbitrary certificate of attendance. For normal AI use, there is no generally prescribed “EU AI Act compliance certificate”. What is useful instead is traceable internal documentation of the measures actually taken.

Evidence of responsible AI use

I support organisations in building such evidence pragmatically.

This typically includes:

  1. inventory of the AI systems in use

  2. simple risk assessment of use cases

  3. clarification of permitted and prohibited uses

  4. short AI usage guideline

  5. training on safe AI use

  6. documentation of content, participants and open measures

  7. assignment of responsibilities

  8. recommendations for next steps

The result is not an official certification and not a blanket legal guarantee. It is a robust organisational record: the AI systems in use are known, risks have been assessed, employees have been prepared and rules are documented.

Recommendation

The better strategy is:

approve a secure company solution, set clear rules, enable employees and limit private shadow AI.

This creates productivity gains while improving control over data protection, quality and information security.

If you want to use AI more safely in your organisation and address the requirements around GDPR and the EU AI Act pragmatically, I support you with inventory, training, usage guidelines and evidence of responsible AI use.

Allgemein

Does the EU AI Act also apply to small organizations?

Yes. The law applies to anyone offering or operating AI systems in the EU – regardless of size. Requirements scale with the application's risk.

What does AI literacy mean concretely?

Users understand how the AI works, where its limits lie (e.g. hallucinations) and what ethical and legal risks exist. This can happen through workshops, e-learning or internal guides.

Do we need to document every AI use?

For minimal-risk systems there's no strict documentation requirement like for high-risk systems. For internal due diligence, a simple list of used tools and their purpose is highly recommended.

Are ChatGPT or Microsoft Copilot automatically risky?

No. In standard text-work use, they count as general-purpose AI with limited transparency duties. They become risky through the context of application – e.g. automated rejection of applicants.