Know where AI is already being used.
List customer chat, voice, content generation, recruitment, analytics, fraud, personalisation, internal assistants, agents, and AI features inside existing software.
The EU AI Act uses a risk-based approach and different obligations apply at different times. This briefing is a practical starting point, not legal advice: identify what you use, how it affects people, who supplies it, what information it touches, and who is accountable.

ONE BRIEFING · 6 DECISION LAYERSList customer chat, voice, content generation, recruitment, analytics, fraud, personalisation, internal assistants, agents, and AI features inside existing software.
Responsibilities can depend on your role, the use case, and whether you substantially modify a system. Record the supplier, model, purpose, users, and contractual responsibilities.
Consider who may be affected, what decision or action occurs, the sensitivity of the information, the possibility of unfair impact, and whether the use may fall into prohibited, transparency, or high-risk categories.
EU transparency obligations applying from August 2026 cover certain interactive AI systems and generated or manipulated content. Determine where notices, labels, or machine-readable marking are required.
Define who can approve, stop, correct, investigate, and change the system. Keep evidence of the intended use, evaluation, data, permissions, incidents, and operational decisions.
High-risk timelines have been extended for specific categories, but an inventory, literacy, supplier review, transparency, ownership, and evidence are useful immediately. Confirm legal duties with qualified counsel.
The EU AI Act applies through a risk-based structure, and timing or duties can depend on the system, use, actor role, and sector. This briefing is not legal advice. A business can still prepare useful operational facts now so qualified legal and risk teams are not asked to classify an unknown collection of tools after a deadline arrives.
Include customer chat and voice, content generation, recruitment, employee tools, fraud or risk scoring, personalisation, analytics, document processing, decision support, agents, and AI features embedded in existing software. For each, record the supplier, model or service, intended purpose, users, affected people, data, outputs, actions, geography, business owner, technical owner, and current approval status.
A business may provide, deploy, import, distribute, or substantially modify a system, and different responsibilities may follow. Classify the actual intended use and consequence rather than the marketing name. Review prohibited practices, high-risk categories, transparency duties, general-purpose AI dependencies, sector rules, employment or consumer impact, and contractual allocation with appropriately qualified counsel.
Identify where people should know they are interacting with AI or seeing generated content, how notices are presented, and how records are retained. Define which outputs are recommendations, which actions need approval, how a person intervenes, what information supports review, how affected people can reach help or correction, and how the organisation stops or recovers from unsuitable behaviour.
Maintain intended-use records, risk assessment, data and source information, supplier documentation, testing, limitations, access, oversight, training, transparency decisions, logs, incidents, changes, and release approvals in a controlled location. The right evidence will vary by classification and role. Review the inventory when a vendor, model, data source, geography, user group, action, or purpose changes.
Record the system, purpose, supplier, model, data, users, affected people, actions, and accountable owner.
Check where people must be told they are interacting with AI or seeing generated or manipulated content.
Keep policies, evaluations, oversight, access, logs, incidents, supplier information, and approved changes together.