EU AI Act & AI Enablement
Paid enterprise AI tools like Copilot remain blocked while personal AI is used. This creates shadow AI with real data privacy risks.

Generative AI is already used in many companies, associations and social organisations — often regardless of official approval. People use it for spell-checking, translation, email drafts, summaries, research and generating ideas.
The benefit is obvious. Blanket bans rarely stop adoption; instead, uncontrolled shadow IT appears through personal ChatGPT or Gemini accounts, private devices or free translation services.
The actual risk
With private accounts, organisations lose control over the data entered, over contract terms, privacy, storage, deletion, auditability, and access by people who have left.
Translation services such as DeepL are equally critical when internal, confidential or personal text is entered without an enterprise agreement.
The problem is rarely AI use itself. The problem is unregulated AI use — without approval, without training, and without anyone accountable.
The better path
Many organisations do not need a large AI strategy first. They need a solid, secure foundation:
approved tools
clear rules for company data
usage guidelines people understand
trained staff
documented responsibilities
regular review of new applications
Microsoft 365 Copilot Chat can be a sensible starting point in M365 environments. Use through a business account draws on enterprise protection, though Copilot still does not replace clear policies or human review.
GDPR and the EU AI Act
The GDPR applies to AI use as well. Personal, confidential and business-critical data may only be processed within authorised boundaries.
The EU AI Act requires responsible deployment. A central requirement is AI literacy for staff operating AI systems: understanding which tools are allowed, which data may be used, what can go wrong, and where human review is necessary.
The EU AI Act came into force on 1 August 2024. The AI literacy obligation has applied since 2 February 2025; further central provisions apply from 2 August 2026. Organisations should therefore clarify now which AI is in use, which rules apply, and how staff can work with it safely.
Importantly, this is not about generic attendance certificates. Standard AI use has no mandated "EU AI Act compliance badge". What matters is practical internal documentation of the measures actually taken.
Evidence of responsible AI use
I help organisations put such documentation in place pragmatically. That typically includes:
an inventory of the AI systems in use
a simple risk assessment of the use cases
clarity on what is permitted and what is not
a short AI usage policy
training on safe AI use
documentation of topics, participants and open actions
named responsibilities
recommendations for next steps
The result is not a government certification or a blanket legal guarantee. It is a reliable organisational record: the AI tools in use are catalogued, the rules are written down, and the people working with them know where the boundaries lie.