De-risking a Copilot rollout
Clarify before rollout which data Copilot can see, who is allowed to do what, and how it is documented.
The EU AI Act is in force — and it applies not only to companies that build AI but to everyone who uses it. For mid-sized companies this mainly means: knowing which AI is in the house, classifying it correctly, enabling employees, and documenting both together with GDPR. We put that into a form that works in daily practice.
Regulation (EU) 2024/1689 has been in force since 1 August 2024 and applies in stages. Since 2 February 2025 prohibited practices are banned and the AI literacy obligation under Article 4 applies: anyone operating AI systems must ensure that the staff involved understand how they work and where their limits are. Since 2 August 2025 the rules for general-purpose AI models and the governance and penalty framework apply; since 2 August 2026 the regulation is in principle fully applicable. The deadlines for high-risk systems have been adjusted several times during the legislative process — which dates apply to you specifically is something we check case by case against the current state of the law.
For most mid-sized companies the good news is: what you actually use rarely falls into the high-risk category. A Copilot in Microsoft 365, a chatbot on the website or text classification in the inbox are typically low-risk systems or systems with transparency obligations. It becomes critical where AI decides about people — in recruiting, credit scoring or performance assessment. These are exactly the cases you need to know about before someone introduces them without consultation.
We therefore work from reality rather than from the legal text: first an inventory of what is actually in use — including the tools business units run without IT approval. Then classification per system by risk class and role, combined with the data protection view: which data flows where, on what legal basis, under which data processing agreement. From this we build a lean set of rules, an understandable usage policy for employees, and training that genuinely satisfies the literacy obligation rather than just ticking it off.
Clarify before rollout which data Copilot can see, who is allowed to do what, and how it is documented.
Record which AI tools business units already use — then bring them into order instead of banning them.
Hands-on training for employees who actually work with AI, with evidence for your documentation.
Inventory: which AI is actually in use?
Classification by risk class and role
Policy, documentation and processing agreements
Training and regular review
We advise on technical and organisational matters and do not replace legal advice. The AI Act deadlines — particularly for high-risk systems — have been adjusted several times; we check the state applicable to you case by case and work with your legal advisers where needed.
Still have open questions? We're happy to clarify them in an initial call.
We help you deploy AI where it creates real value — not where it is simply fashionable.
Documents, emails, tickets — we automate what repeats.
Custom AI assistants based on your data — GDPR-compliant, EU-hosted.
Free initial consultation, 30–45 minutes, remote. An honest assessment — even if the answer is that you don't actually need it.