Logo webu

AI Act in Practice: How to Prepare Your Organization for AI Regulation

 ​

Prague, August 6, 2026

 ​

Artificial intelligence (AI) is no longer just a technological experiment or a topic for IT departments. It has become an integral part of everyday business operations—from customer support and marketing to data analysis and internal automation. However, AI adoption is often progressing faster than organizations can establish clear policies, responsibilities, and governance frameworks.

Today, employees across organizations use AI tools even without formal management approval. Alongside officially approved solutions, this has led to the rise of shadow AI—the use of unauthorized AI tools outside the oversight of IT and security teams. This creates significant risks, particularly when it comes to handling sensitive data, protecting intellectual property, and ensuring compliance with internal policies and regulatory requirements.

AI Often Operates Without Clear Governance

Content creation, data analysis, presentation preparation, and the automation of routine tasks are now common AI use cases. The challenge arises when organizations lack visibility into which AI tools employees are using and what data is being shared with them.

A typical example of shadow AI is employees using public AI tools such as ChatGPT, Claude, or Gemini to process internal documents without organizational approval. In many cases, organizations have little or no visibility into what information is being entered into these systems or how that data is subsequently processed.

As a result, sensitive business information may leave the organization's environment without adequate control. Companies lose visibility into where their data ends up, who can access it, and whether its use complies with internal policies.

AI governance establishes clear rules for the safe, transparent, and responsible use of artificial intelligence in companies.

AI Act in Practice

The AI Act addresses these challenges. It is the European regulation governing the development, deployment, and use of artificial intelligence systems. Its objective is to ensure that AI is used safely, transparently, and responsibly while fostering innovation.

The AI Act is not simply another European regulation, nor is it intended to prohibit or restrict the use of AI. Instead, it provides a structured framework for managing AI-related risks and establishes rules for organizations that develop, provide, or use AI systems.

Organizations will need to demonstrate how AI systems are used, what data they process, who is responsible for them, and how associated risks are managed. In practice, this includes maintaining an inventory of AI systems, implementing AI risk management, controlling data usage, ensuring transparency, defining clear responsibilities, and continuously monitoring AI systems.

The AI Act applies to organizations that develop, provide, or use AI systems. The strictest requirements apply to high-risk AI systems, including those used in areas such as human resources, education, healthcare, and critical infrastructure.

Simply Banning AI Doesn't Work

Many organizations respond to the rise of AI by attempting to restrict or ban public AI tools. In practice, however, this approach rarely improves security. Employees continue using AI—only without the organization's knowledge.

"The most effective approach is to establish clear and practical policies. These should define which AI tools are approved, what data may be entered into AI systems, who authorizes their use, how outputs should be verified, and which processes employees are expected to follow," ​ ​says ​Tomáš Mertl, Senior Consultant at axelum.

The goal is not to slow innovation but to create an environment where AI can be used safely and responsibly.

AI Governance as the Foundation of AI Management

Organizations that want to benefit from AI over the long term need an effective AI governance framework. This combines internal policies, technological and security controls, clearly defined responsibilities, employee training, and continuous monitoring of AI usage.

Preparing for the AI Act also involves improving AI literacy. Organizations should ensure that employees understand the capabilities, limitations, and risks of the AI systems they use. A strong level of AI literacy helps prevent mistakes, security incidents, and the misuse of AI tools.

Well-designed AI governance is not an obstacle to innovation. On the contrary, it enables organizations to adopt AI faster, with lower risk and in compliance with regulatory requirements. At the same time, it supports AI compliance and sustainable AI management across the organization.

AI Requires Governance, Not Improvisation

Artificial intelligence is fundamentally changing how organizations operate. The key question is no longer whether companies will use AI, but how they will govern and control it.

"At axelum, we help organizations implement AI in a way that delivers value rather than creating risk—from defining governance policies to establishing effective oversight of AI usage across the organization," ​adds ​Jakub Bretšnajdr, Sales Representative at axelum.

The AI Act provides organizations with a framework for establishing clear governance, reducing risks, and ensuring the safe and responsible use of AI in practice.

FAQ

Learn what the AI Act means for your organization, who the new requirements apply to, how to approach generative AI, what shadow AI is, and how to prepare for the safe and responsible use of artificial intelligence.

What is the AI Act?
The AI Act is a European regulation governing the development, deployment, and use of artificial intelligence systems. Its objective is to ensure the safe, transparent, and responsible use of AI while fostering innovation.
Who does the AI Act apply to?
The AI Act applies to organizations that develop, provide, or use AI systems as part of their operations. Specific obligations vary depending on the organization's role and the risk level of the AI system involved.
Does the AI Act also apply to the everyday use of ChatGPT?
Yes. If an organization uses generative AI tools as part of its operations, it should have visibility into how they are used, what data is shared with them, and the associated risks.
When does the AI Act take effect?
The AI Act entered into force in 2024. Its requirements are being introduced gradually in several phases.
What is shadow AI?
Shadow AI refers to the use of AI tools without the organization's knowledge or formal approval.

Is Your Organization Ready for the AI Act?

We help organizations establish AI governance, manage AI risks, and ensure the secure and compliant use of artificial intelligence in line with the European AI Act.
Book a consultation
All infosec
We are an information security company. Our purpose is to safeguard the clients' most valuable information and protect their business.

© 2026 Axelum s.r.o.

Contact

Axelum s.r.o.

CIN: 25639056

VAT ID: CZ699004029

V Kapslovně 2767/2

130 00 Prague CZ

info@axelum.eu

+420 221 400 111


Created by uuWebKit
document_check.svg
We use cookies on this website to ensure its functionality and to personalise ads, solely with your consent and in accordance with our Cookies Policy.

By clicking on the "Accept cookies" button, you consent to the use of selected cookies and agree to the transfer of behavioural data for the display of targeted advertising on social and advertising networks. You can choose which information you want to share with us by clicking on the Cookie settings button.