What the AI Act actually requires of a company that only uses tools

Regulation (EU) 2024/1689 splits the roles. Whoever builds and places an AI system on the market is a provider. Whoever uses it under their own authority in a professional activity is a deployer — Article 3(4). If you buy a subscription to a general assistant and your team types into it, you are a deployer. The model provider's obligations do not become yours.

For a deployer of a general-purpose assistant, three things bind in practice.

First, AI literacy — Article 4. In application since 2 February 2025. Regulation (EU) 2026/1744, published on 24 July 2026 and in force from 27 July 2026, softened the wording: providers and deployers "shall take measures to support the development of AI literacy" of their staff, and the article now says explicitly that this does not require guaranteeing any specific level of literacy in any individual. That is not an exemption. You still have to do something, and be able to show it. Use role-specific examples and check understanding. An attendance list records participation; no fixed training duration guarantees compliance.

Prohibited practices — Article 5. Review the actual use case before a pilot. The workplace and education prohibition on emotion inference concerns systems using biometric data, subject to the stated medical and safety exceptions. Text-only sentiment analysis is not automatically that prohibited practice, but may raise other employment, data-protection or AI Act issues.

Third, transparency — Article 50, in application from 2 August 2026. Three of its duties sit with the deployer rather than the provider. If you use an emotion recognition or biometric categorisation system, you inform the people exposed to it. If you generate or manipulate image, audio or video that appears authentic — a deepfake — you disclose that it is artificially generated. If you publish AI-generated text to inform the public on matters of public interest, you disclose that too, unless the content went through human review and a person holds editorial responsibility for it. The information has to be clear and given no later than the first interaction.

The deployer obligations for high-risk systems in Article 26 do not apply yet. Regulation (EU) 2026/1744 moved them to 2 December 2027 for systems designated under Annex III and 2 August 2028 for systems embedded in Annex I products. Deferred, not cancelled — and if AI takes part in hiring, employee evaluation or credit decisions, that is a different conversation.

Article 25 can shift provider responsibilities for high-risk systems in specified circumstances, including branding, substantial modification or changing intended purpose so that a system becomes high-risk. It is not a blanket rule that every renamed tool changes legal role. Product teams should assess the system, use and applicable conditions before launch.

What the GDPR and your contracts require anyway

This is where the real weight sits, and it sat there before there was any AI law.

Entering personal data into a prompt is processing. Establish a lawful basis, compatible purpose and data minimisation. Determine the provider’s actual role: where it acts as processor, Article 28 terms are needed; other roles require their own assessment. Check international transfers outside the EEA under Chapter V, including remote access. Article 22 requires separate review of solely automated decisions producing legal or similarly significant effects.

Beyond the GDPR there are three limits people forget because they do not look like cybersecurity:

  • Confidentiality clauses in your customer contracts. Most prohibit disclosure to a third party without consent. Pasting text into somebody else's tool is disclosure to a third party.
  • Trade secrets. Once material has gone into a service whose terms allow input to be used for training, it is hard to argue that reasonable steps were taken to keep it secret.
  • Sectoral duties — banking secrecy, professional secrecy, a regulator's requirements. Financial entities should add the DORA third-party regime for ICT service arrangements; additional requirements apply when critical or important functions are supported.

If you are not sure which regime you are in at all, start with which one applies to you — DORA, NIS2 or neither.

Where the data actually goes: consumer versus business tiers

Product terms change often, so what follows is the durable difference rather than the current text of anyone's page.

Check the exact account type and terms. Personally managed accounts can leave the company without central control over access, sharing and retention. Training use, opt-outs and data-processing terms vary by provider and product; do not infer them from a “free” label.

A business plan may offer company administration, contractual data protections and additional controls. SSO, audit logs, retention choices and data residency can depend on the tier. Verify the features and terms you will actually buy; a business label does not settle risk.

The difference is not the model. The difference is the contract and who administers the account. So ask every tool two questions and get the answer in writing, for the tier you actually pay for: is my input used to train a model, and can an administrator see who is using it.

One more thing. The chat window is the visible part. Browser extensions, bots that join meetings and take notes, coding assistants inside the development environment, and features quietly added to a SaaS subscription you already have all send data down the same path, and almost none of them appear on anybody's list.

The three things that cause incidents in practice

Confidential material pasted into a prompt. A contract, a database export, source code from a customer system, a payroll list. Usually not carelessness — usually someone in a hurry.

Unreviewed output sent outside. A reply to a customer, an analysis to a regulator, a legal note with an invented citation, a financial table with a plausible wrong number. The signature at the bottom is yours and so is the liability. Automated checks can help, but a named reviewer must verify the material claims and understand the limits.

Shadow AI. Tools nobody knows are in use. After an incident the customer or the supervisory authority asks one question: where did the data go. "We do not know" is the most expensive available answer.

Using AI is not the problem. Using it without rules is.

The shortest policy that actually holds

One page. Eight sections. The wording below is illustrative — replace the roles and the lists with your own.

Section The question it answers Example line (illustrative)
Scope Who and which tools this covers "These rules apply to all employees, interns and contractors using AI tools for company work — whoever owns the account and whichever device is used."
Approved tools What may be used today "Only the tools listed in Annex 1, and only through company accounts. Use through a personal account is not permitted."
Approving a new one Who says yes, and how fast "A new tool may be used after written approval by [role] and entry in Annex 1. An answer is given within 5 working days."
What never goes in a prompt What is forbidden as input "Do not enter: customer or employee personal data, the content of documents under an NDA, source code from customer systems, passwords and keys, unpublished financial figures."
Check before it leaves Who is answerable for the result "Any text, calculation or code produced with AI is checked by [role] before it leaves the company. Numbers, citations and legal references are verified. The person who sends it is responsible for it."
Disclosure When we say it is AI "Artificially generated images, audio and video are labelled. Publications on matters of public interest are reviewed by [role], who holds editorial responsibility."
Reporting a problem What someone who slipped up does "If you entered something you should not have, tell [role] the same day. Good-faith reporting is encouraged; the priority is containment and learning, with conduct assessed fairly."
Training and review How we show we did something "Every new joiner takes a one-hour introduction in their first month. Annex 1 and these rules are reviewed every six months."

Date it, have the management body sign it, and put it where people log in — not in a folder on a shared drive.

Can an employee enter customer data into ChatGPT?

The practical answer depends on the approved task, data category, account and destination. A business subscription alone does not authorise uploading every customer document. Check the contract, lawful processing basis where personal data is involved, permitted recipients and the organisation's approved configuration.

OpenAI states that business product data is not used for model training by default. That is a specific product commitment, not a conclusion that all retention, access, international-transfer or contractual questions are solved. Connected apps and external actions can introduce additional destinations. Verify the actual service and settings instead of relying on the name in a colleague's screenshot.

Proposed input Safer working decision
Already public product description Use an approved tool for the defined purpose and review the output
Support ticket with customer identifiers Remove unnecessary identifiers and obtain the required authorisation for remaining data
Contract or confidential attachment Check disclosure restrictions and the approved environment before upload
Password, recovery code or live token Keep it out of prompts and attachments

For a fictional drafting task, replace “Customer Elena Petrova, account 48291, late payment after medical leave” with “Draft a neutral payment reminder for a customer whose invoice is overdue.” The second prompt preserves the writing task without those details. This does not make every edited document anonymous: context, rare events and linked information may still identify a person.

Use the customer-data decision sheet to record the task, necessary data, tool, recipients, retention check and approver. If those facts are unknown, use synthetic material while the owner decides. An employee needs a usable route to approval rather than a vague instruction to “be careful”. The data and output guide also covers checking the generated result before it reaches a customer.

What to do first

  1. Build the list in three days. Ask every team which AI tools they use and with which account. Check expense reports for subscriptions, browser extensions, and bots that join meetings. The list is always longer than expected.
  2. Pick one or two tools and move them to a business tier. Company accounts, single sign-on, a named administrator. Verify the controls and terms before migration; this addresses only part of the exposure.
  3. Write the page from the table above with your roles and your data categories. One afternoon.
  4. Run the one-hour session with real examples from your own work, including one case where AI was plausibly wrong. Keep the attendance list; that is also your Article 4 evidence.
  5. Check whether AI takes part in any decision about a person — hiring, evaluation, access to a service, credit. If it does, stop and review that separately.
  6. Write one name next to the rule "who checks before it goes out". A rule with no owner is not a rule.

The boundary

This article covers a deployer of a general assistant. It does not cover embedding AI in your own product, training or fine-tuning a model, putting your brand on somebody else's system, or using AI for decisions about people. Each of those moves the regime and needs its own review.

It also does not cover sectoral supervision. A financial entity using an AI service for an important function has separate DORA duties. Who inside the company is answerable for any of this is a separate question, taken up in CISO, virtual CISO or the IT manager. And if you are thinking about AI from the other side — as a monitoring tool rather than a risk — see what AI actually does in security monitoring.

If you want this page written for your data, your tools and your contracts, that is the scope of the AI governance review.

Note. General information, not legal advice. Applicability depends on the specific entity, activity, licence, size, group structure and national implementation.

Use the AI data and output checklist to define the rules, and the policy adoption guide to check whether people can apply them.