AI with control: How IT leaders can navigate the EU AI Act
No video selected
Select a video type in the sidebar.
Generative AI, Copilot and AI agents are creating new opportunities to streamline ways of working and generate business value. But as adoption increases, so does the need for control. For IT leaders, AI is therefore no longer just about which technology the organisation should use. It is also about how AI is used, what data is processed and which risks need to be managed.
Natalie Mattsson, Senior Information Security Specialist at Iver, helps us understand what the EU AI Act means in practice and what IT leaders need to consider as AI adoption increases.
What is the EU AI Act?
The EU AI Act is the European Union’s regulatory framework for artificial intelligence. Its purpose is to establish clear rules for how AI can be developed and used, while promoting innovation and protecting people from privacy and security risks.
The regulation is based on a risk-based approach, where AI systems are classified according to the level of risk they may pose. Requirements are higher for AI that can have a significant impact on, for example, individuals’ rights, safety and access to essential services.
For businesses, this includes new requirements relating to AI literacy, transparency, documentation and governance – depending on how AI is used and what type of system is involved.
The EU AI Act also applies to the AI systems and AI-based services that organisations purchase and use. For IT leaders, it is therefore important to understand how AI is embedded in the services they procure and what requirements apply to the supplier. As an organisation that both uses AI and delivers services where AI is part of the solution, Iver needs to maintain control over how AI is used in our services and ensure that they are delivered in a secure and responsible way.
The EU AI Act is an IT issue
It is easy to view the EU AI Act as purely a legal matter. In practice, however, many of the responsibilities have a direct impact on IT. IT has visibility across infrastructure, shadow IT, data leakage and licence management.
IT therefore needs to be able to answer questions such as:
- Which AI services are currently being used across the organisation – both officially and unofficially?
- What information are employees allowed to share with AI services?
- Which AI solutions are being used in business-critical processes?
- Who is responsible for our different AI solutions?
- Do employees have the knowledge they need to use AI safely?
At its core, this is similar to what IT departments already manage across security, data protection and governance: creating control over technology without slowing down innovation.
Start by mapping your AI usage
One of the biggest challenges is that AI adoption often moves faster than organisational governance. Employees experiment with new tools on their own initiative, while the business starts integrating AI into its processes.
Start with a simple question:
What AI are we already using?
Map the tools being used, what data is being processed and how AI is being applied across the organisation. From there, you can assess risks and prioritise what needs to be addressed.
From policy to practical control
An AI policy is a good starting point, but it needs to be complemented by practical ways of working. This could include:
- Mapping AI services and use cases.
- Assessing risks based on data and business context.
- Defining which tools are approved and how they may be used.
- Securing data, identities and access.
- Training employees on the opportunities and risks associated with AI.
The EU AI Act is based on a risk-based approach, meaning that different AI systems are subject to different requirements depending on how and where they are used.
Regulation and innovation are not opposites
The EU AI Act does not have to be a barrier to innovation. Clear guidelines can actually make it easier for the organisation to use AI in a safe and responsible way.
When employees know which tools they can use, what information they can share and which use cases are approved, it becomes easier to scale AI from experimentation to real business value.
For IT leaders, the goal is therefore to move from “Can we use AI?” to “How do we create the right conditions to use AI in a secure, responsible and value-generating way?”
Three questions to ask your management team today:
- Mapping: Do we have a complete picture of all the AI actually being used across the organisation?
- Data security: Do we have safeguards in place to prevent sensitive company data from being shared with public AI models?
- Governance: Do we have clear rules and defined ownership for our AI initiatives?
AI is not just about what the technology can do. It is equally about creating the right conditions to use it safely, responsibly and with real business value.
As a provider of IT and AI services, Iver works with AI in practice – from infrastructure and security to solutions where AI is an integrated part of the service. This gives us a strong understanding of the technical considerations and requirements that need to be addressed when AI is used and delivered.
At Iver, we help you navigate the rapidly evolving AI landscape and create secure, robust and sustainable foundations for using AI across your organisation. Learn more about our Data & AI services