leuschner.ai
EU AI Act & the safe use of AI
TL;DR / Quick Answer
The EU AI Act has been in force since 1 August 2024 and sets new global standards for the regulation of artificial intelligence. For organizations, this means: AI literacy becomes mandatory. This guide translates the legal requirements into a practical work logic for everyday life.
Generative AI is already being used in many companies, associations and social organisations. Often regardless of whether it has been officially approved.
Employees use AI, for example, for spelling, translations, email drafts, summaries, research and ideas.
The benefit is obvious. A blanket ban therefore often fails to prevent its use. Instead, uncontrolled solutions emerge via private ChatGPT or Gemini accounts, private smartphones, personal email addresses or freely accessible translation services.
The real risk
With private AI accounts, the organisation loses control over entered data, contractual conditions, data protection, storage, deletion, traceability and access by former employees.
Translation services such as DeepL are also critical if internal, confidential or personal texts are entered without an appropriate company contract.
The problem is therefore rarely the use of AI itself. The problem is unregulated AI use without approval, without training and without traceable responsibility.
The better way
Many organisations do not need a large AI strategy at first. They need a secure basis:
approved tools
clear rules for company data
understandable usage guidelines
trained employees
documented responsibilities
regular review of new applications
Microsoft 365 Copilot Chat can be a useful starting point for many Microsoft 365 environments. When used with a business account, the protection mechanisms of the Microsoft 365 environment apply. Nevertheless, Copilot also does not replace clear rules, data classification or professional review of results.
GDPR and the EU AI Act
The GDPR also applies to AI use. Personal, confidential and business-critical data may only be processed within the permitted framework.
The EU AI Act also requires a responsible approach to AI. A central element is the AI literacy of the people who use AI systems. They must understand which tools are allowed, which data may be entered, where AI can make mistakes and when human review is required.
What matters is: this is not about an arbitrary certificate of attendance. For normal AI use, there is no generally prescribed “EU AI Act compliance certificate”. What is useful instead is traceable internal documentation of the measures actually taken.
Evidence of responsible AI use
I support organisations in building such evidence pragmatically.
This typically includes:
inventory of the AI systems in use
simple risk assessment of use cases
clarification of permitted and prohibited uses
short AI usage guideline
training on safe AI use
documentation of content, participants and open measures
assignment of responsibilities
recommendations for next steps
The result is not an official certification and not a blanket legal guarantee. It is a robust organisational record: the AI systems in use are known, risks have been assessed, employees have been prepared and rules are documented.
Recommendation
The better strategy is:
approve a secure company solution, set clear rules, enable employees and limit private shadow AI.
This creates productivity gains while improving control over data protection, quality and information security.
If you want to use AI more safely in your organisation and address the requirements around GDPR and the EU AI Act pragmatically, I support you with inventory, training, usage guidelines and evidence of responsible AI use.
EU AI Act Compact
Understand essential obligations and implement them securely.
Adopt AI Securely
Legally secure, practical and with clear guidelines.
Build Prompt Systems
Structured systems for better, reproducible results.
Knowledge Management
Structure knowledge, make it accessible and use it meaningfully.
Allgemein
Does the EU AI Act also apply to small organizations?
Yes. The law applies to anyone offering or operating AI systems in the EU – regardless of size. Requirements scale with the application's risk.
What does AI literacy mean concretely?
Users understand how the AI works, where its limits lie (e.g. hallucinations) and what ethical and legal risks exist. This can happen through workshops, e-learning or internal guides.
Do we need to document every AI use?
For minimal-risk systems there's no strict documentation requirement like for high-risk systems. For internal due diligence, a simple list of used tools and their purpose is highly recommended.
Are ChatGPT or Microsoft Copilot automatically risky?
No. In standard text-work use, they count as general-purpose AI with limited transparency duties. They become risky through the context of application – e.g. automated rejection of applicants.