All insights
    Max Västhav

    The first AI Act step isn't a policy. It's an inventory.

    Most companies that start with the AI Act make the same mistake: they write a policy before they know what they use.

    aieu-ai-actgovernancesmall-business

    Most companies that start with the AI Act make the same mistake: they write a policy before they know what they use.

    That's like writing a fire safety policy without knowing where the smoke detectors are.

    AI is already in use — scattered and undocumented

    In a typical SMB with 10–50 employees, AI already exists in more places than management thinks:

    • ChatGPT/Copilot — employees use them daily for emails, summaries, code suggestions.
    • CRM AI features — lead scoring, suggested next steps, automatic summaries.
    • Support tools — chatbots, AI-suggested replies, case classification.
    • HR tools — CV screening, interview scheduling, performance analytics.
    • Marketing — AI-generated text, image generation, SEO tools.
    • Finance — automatic invoice matching, anomaly detection.

    Nobody has listed them. Nobody has classified them. Nobody knows who's responsible.

    An AI register in 30 minutes

    Start with a spreadsheet. Seven columns are enough:

    SystemUsageAffected personsRisk classOwnerApproval required?Next review
    ChatGPTEmail drafts, text editingInternal + customers (if emails sent)Minimal/TransparencyAnnaNo (internal), Yes (external)2026-Q3
    HubSpot AILead scoringProspects, customersMinimalErikNo2026-Q3
    Recruitment AICV screeningJob applicantsHigh riskHR leadYes2026-Q2

    You don't need to finish in one day. Start with the systems that affect external people — customers, job applicants, partners.

    Three questions per system

    For each AI system in the register, ask three questions:

    1. Who is affected if AI is wrong?

    If the answer is "only me" (e.g., ChatGPT for internal notes) — low risk. If the answer is "job applicants" or "customers receiving automated decisions" — high risk.

    2. Does the affected person know AI is involved?

    If not — you have a transparency problem that needs fixing regardless of risk class.

    3. Who in the company owns this system?

    If the answer is "nobody" — that's your first problem to solve.

    Why policy without inventory fails

    An AI policy that says "we use AI responsibly" without knowing which AI is in use is meaningless.

    It's like GDPR without a data register. The words exist, but the control doesn't.

    With a register, you can:

    • Prioritize — focus on high-risk systems first.
    • Act — add transparency and approval where needed.
    • Demonstrate — to customers, auditors, and authorities that you're in control.
    • Update — when new systems are added or old ones removed.

    The AI Act context

    The AI Act doesn't explicitly require a register for all companies. But for deployers of high-risk systems, the documentation requirements practically demand an inventory.

    And regardless of legal requirements: a company that knows which AI systems it uses makes better decisions than one that doesn't.

    Next step

    Open a new spreadsheet. Create seven columns. List all AI systems you use — start with those affecting customers and employees.

    That's your inventory. That's your first AI Act step.

    Cookies. Privacy