EU AI Act & AI Empowerment
Paid enterprise AI such as Copilot remains blocked, whilst personal AI is used. This gives rise to ‘shadow AI’, which poses a genuine data protection risk.

Generative AI is already being used in many companies, associations and social organisations. Often regardless of whether it has been officially approved.
Employees use AI, for example, for spelling, translations, email drafts, summaries, research and ideas.
The benefit is obvious. A blanket ban therefore often fails to prevent its use. Instead, uncontrolled solutions emerge via private ChatGPT or Gemini accounts, private smartphones, personal email addresses or freely accessible translation services.
The real risk
With private AI accounts, the organisation loses control over entered data, contractual conditions, data protection, storage, deletion, traceability and access by former employees.
Translation services such as DeepL are also critical if internal, confidential or personal texts are entered without an appropriate company contract.
The problem is therefore rarely the use of AI itself. The problem is unregulated AI use without approval, without training and without traceable responsibility.
The better way
Many organisations do not need a large AI strategy at first. They need a secure basis:
approved tools
clear rules for company data
understandable usage guidelines
trained employees
documented responsibilities
regular review of new applications
Microsoft 365 Copilot Chat can be a useful starting point for many Microsoft 365 environments. When used with a business account, the protection mechanisms of the Microsoft 365 environment apply. Nevertheless, Copilot also does not replace clear rules, data classification or professional review of results.
GDPR and the EU AI Act
The GDPR also applies to AI use. Personal, confidential and business-critical data may only be processed within the permitted framework.
The EU AI Act also requires a responsible approach to AI. A central element is the AI literacy of the people who use AI systems. They must understand which tools are allowed, which data may be entered, where AI can make mistakes and when human review is required.
What matters is: this is not about an arbitrary certificate of attendance. For normal AI use, there is no generally prescribed “EU AI Act compliance certificate”. What is useful instead is traceable internal documentation of the measures actually taken.
Evidence of responsible AI use
I support organisations in building such evidence pragmatically.
This typically includes:
inventory of the AI systems in use
simple risk assessment of use cases
clarification of permitted and prohibited uses
short AI usage guideline
training on safe AI use
documentation of content, participants and open measures
assignment of responsibilities
recommendations for next steps
The result is not an official certification and not a blanket legal guarantee. It is a robust organisational record: the AI systems in use are known, risks have been assessed, employees have been prepared and rules are documented.
Recommendation
The better strategy is:
approve a secure company solution, set clear rules, enable employees and limit private shadow AI.
This creates productivity gains while improving control over data protection, quality and information security.
If you want to use AI more safely in your organisation and address the requirements around GDPR and the EU AI Act pragmatically, I support you with inventory, training, usage guidelines and evidence of responsible AI use.