Artificial intelligence has moved quickly from experimentation to everyday business use. Companies are using AI tools to draft documents, analyse data, support customer service, automate workflows, screen information, detect patterns, and improve decision-making. In many cases, these tools can save time and reduce manual work. However, as AI becomes more embedded in business operations, it also creates new responsibilities.
This is where the EU AI Act becomes important.
The EU AI Act and Business Risk
The EU AI Act entered into force on 1 August 2024 and is being applied in stages. According to the European Commission, the Act will become fully applicable on 2 August 2026, with some exceptions applying earlier. The Commission describes it as a risk-based legal framework designed to ensure that AI systems used in the EU are safe, transparent, traceable, non-discriminatory, and subject to human oversight. (European Commission)
For businesses, the key point is not simply that there is a new regulation. The key point is that AI is now moving into the same category as other areas of business risk. It needs to be understood, documented, controlled, and monitored.
Informal AI Use and Data Risk
Many businesses are currently using AI informally. Employees may use public AI tools to summarise documents, prepare emails, review spreadsheets, generate marketing content, or support internal research. In some cases, management may not even know exactly which tools are being used or what information is being entered into them.
That creates risk.
If staff enter confidential client data, financial information, employee records, contracts, personal data, or commercially sensitive information into AI tools without clear internal rules, the business may face data protection, confidentiality, and governance issues. Even when the AI tool itself is legitimate, the way it is used inside the organisation may not be properly controlled.
A Risk-Based Approach
The EU AI Act does not treat all AI systems in the same way. It follows a risk-based approach. Some AI practices are prohibited because they are considered unacceptable. Other systems are classified as high-risk and carry stricter obligations. Some tools are subject mainly to transparency requirements, while many lower-risk uses may face limited obligations. The European Commission's implementation timeline notes that the majority of rules, including rules for high-risk AI systems in certain areas and transparency obligations, apply from 2 August 2026. (European Commission AI Act Service Desk)
This matters because businesses need to understand how AI is being used before they can assess whether any obligations apply.
For example, an AI tool used casually to help draft a social media post is very different from an AI system used to assess job applicants, evaluate creditworthiness, monitor employees, support medical decisions, or influence access to essential services. The level of risk depends on the use case.

The table below summarises, at a high level, how the risk-based approach maps different uses to the broad level of obligation described above.
| Risk category | Illustrative use | General obligation |
|---|---|---|
| Prohibited | Practices considered unacceptable | Not permitted |
| High-risk | Assessing job applicants, evaluating creditworthiness, monitoring employees | Stricter obligations |
| Transparency | Chatbots, generated content, automated interactions | Inform stakeholders where relevant |
| Lower-risk | Casual drafting, general research support | Limited obligations |
AI Inventories and Visibility
This is why businesses should start with a simple but important exercise: create an inventory of AI tools and AI-related processes. This does not need to be complicated. Management should know which tools are being used, who is using them, what data is being processed, what decisions the tools support, and whether humans remain involved in final decision-making.
Without this basic visibility, it is difficult to manage AI risk properly.
Employee Training and AI Literacy
Another important area is employee training. The AI Act includes requirements around AI literacy, meaning organisations should ensure that people using or overseeing AI systems have an appropriate level of understanding. This does not mean every employee needs to become a technical expert. It means staff should understand the limitations of AI, the risk of incorrect outputs, confidentiality concerns, data protection requirements, and when human review is necessary.
This is particularly relevant in finance, compliance, audit, legal, HR, and customer-facing roles. AI can assist with work, but it should not replace professional judgement where accuracy, accountability, and regulatory obligations are involved — areas where the right accounting, tax and advisory support remains essential alongside any technology.
Transparency and Governance
Businesses should also pay attention to transparency. If customers, employees, or other stakeholders interact with AI systems, they may need to be informed depending on the nature of the interaction. This can apply to chatbots, generated content, automated decisions, or systems that could influence someone's rights or access to services.
For directors and business owners, the practical issue is governance. Who approves AI tools before they are used? Who reviews the risks? Who checks data protection implications? Who monitors outputs? Who is responsible if the AI produces an incorrect result that affects a client, customer, or employee?
These questions are not theoretical. As AI adoption increases, businesses may face disputes, compliance reviews, client concerns, or regulatory questions about how AI is being used. A company that can show policies, training, documentation, and oversight will be in a stronger position than one relying on informal and undocumented use.
AI Alongside Other Regulations
The EU AI Act should also be viewed alongside other regulations, especially data protection law. Even if a specific AI use is not classified as high-risk under the AI Act, the business may still have obligations under GDPR, confidentiality rules, employment law, consumer protection rules, or sector-specific regulations.
This is especially important for financial services and professional services firms. These businesses often handle sensitive information and are already expected to maintain strong internal controls. AI adoption should therefore be treated as part of the wider compliance framework.
A Practical Approach for Businesses
The purpose is not to stop businesses from using AI. In fact, companies that use AI properly may gain a real advantage. They can reduce repetitive work, improve reporting, strengthen customer service, and support better decision-making. However, the businesses that benefit most will be those that implement AI in a controlled and responsible way.
A practical approach for businesses would include identifying current AI use, reviewing data risks, creating an internal AI policy, training staff, documenting approved tools, assessing higher-risk use cases, and maintaining human oversight for important decisions. If you are unsure how AI fits into your control environment, it is worth speaking to an advisor before committing to new systems.
AI is becoming part of normal business operations. The EU AI Act simply confirms what many businesses should already be doing: understanding how technology is used, managing the risks, and ensuring accountability.
For companies, the message is clear. AI should not be treated as a quick shortcut with no controls. It should be treated as a business tool that requires governance, just like finance systems, compliance processes, and customer data platforms.
The businesses that prepare early will not only reduce compliance risk. They will also build more trust in how they use technology.
Sources & References
- European Commission. "AI Act." Available at: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- European Commission AI Act Service Desk. "Timeline for the Implementation of the EU AI Act." Available at: https://ai-act-service-desk.ec.europa.eu/
- Reuters. "EU sticks with timeline for AI rules." Available at: https://www.reuters.com/
- IBM. "What is the EU AI Act?" Available at: https://www.ibm.com/
