EU AI Act: 7 Practical Governance Updates

eu ai act: EU AI Act: 7 Practical Governance Updates
eu ai act: EU AI Act: 7 Practical Governance Updates

EU AI Act governance changes now affect daily operations

EU AI Act requirements are moving from legal discussion into operational reality for mid-market companies using Microsoft 365, Copilot-style assistants, document automation and AI-supported workflows. Operations leads now sit between compliance, IT and business teams that expect faster automation without increasing regulatory exposure.

For a 120-person manufacturing company in Denmark, the biggest challenge is rarely building an AI model. The real problem is controlling where employees upload customer contracts, HR records and technical documentation. In many organisations, staff already use public AI services outside IT governance. A typical audit shows 15-40 unsanctioned AI interactions per week across departments.

The EU AI Act introduces risk-based obligations that directly affect procurement, documentation, transparency and monitoring. Combined with GDPR and NIS2 pressure, operations leaders need repeatable governance processes rather than one-time policy documents.

Companies that align Microsoft 365 governance with EU AI Act controls typically reduce unmanaged AI usage by 50-70% and cut compliance preparation time by 20-35% within the first year.

The most effective approach combines Microsoft Purview, SharePoint governance, Teams administration and controlled AI deployment policies. The sections below focus on practical operational changes rather than theoretical legal interpretation.

EU AI Act risk classification changes procurement workflows

EU AI Act governance starts with understanding risk classification. Operations teams increasingly discover that AI procurement now requires the same review process previously reserved for cybersecurity or data-processing vendors.

A German logistics company with 85 employees recently reviewed 14 AI-enabled SaaS tools used by customer support, HR and operations planning. Four tools processed employee performance data and customer communication transcripts. Under the EU AI Act framework, these uses required additional transparency, documentation and supplier review.

The operational problem was fragmented procurement. Department managers subscribed directly to AI tools using company cards without legal or IT review. The company solved this by creating a SharePoint-based AI intake process.

In Microsoft 365, the operations team created a dedicated SharePoint list for AI system registration using SharePoint Site Contents -> New -> List. Required fields included:

  • Vendor name and hosting region
  • Type of AI processing
  • Personal data categories
  • Human review process
  • Business owner
  • Risk classification

A Power Automate approval flow routed new submissions to IT, legal and security reviewers. Any system handling employee evaluation, biometric data or automated decision-making triggered mandatory escalation.

The result was measurable within three months. Shadow AI subscriptions dropped from 22 active services to 8 approved platforms, while procurement review time fell from 18 days to 6 days because reviewers worked from structured templates instead of email chains. That governance baseline creates the foundation for documentation and monitoring controls under the EU AI Act.

EU AI Act documentation requirements need operational ownership

EU AI Act compliance fails quickly when documentation stays disconnected from operational systems. Many organisations still store AI policies in static Word documents that nobody updates after approval.

A Swedish professional services company with 140 staff faced this issue during an internal GDPR review. Teams used Microsoft Copilot, AI meeting summaries and document-generation tools, but there was no central record of which departments used which systems, what prompts were allowed or who approved deployments.

The company established a controlled governance workspace inside Microsoft Teams linked to SharePoint. The operations lead created a dedicated Team with channels for policy management, vendor reviews, incidents and AI use cases. Supporting documentation was stored in a SharePoint document library with mandatory metadata.

The key configuration step was enabling structured retention and version tracking. In SharePoint, administrators configured Document Library -> Settings -> Versioning settings to require major versions and retain at least 50 historical versions. This created an auditable trail for governance changes.

The organisation also used Microsoft Purview sensitivity labels to classify AI governance documents containing vendor risk details or personal-data processing information. In the Microsoft Purview compliance portal, administrators published labels through Information Protection -> Labels.

The operational benefit was substantial. Audit preparation time for internal compliance reviews dropped from approximately 32 staff hours per quarter to 11 hours because documentation was searchable, version-controlled and centrally governed. That documentation structure also supports future regulator requests and supplier assessments linked to the EU AI Act.

Microsoft 365 data governance becomes central to AI compliance

EU AI Act obligations overlap heavily with Microsoft 365 data governance because AI systems depend on accessible and properly classified information. Poor SharePoint permissions now create both productivity and compliance risks.

An operations team at a Finnish engineering company discovered that over 18,000 files inside SharePoint Online inherited open access permissions from legacy project sites. Employees using AI assistants could retrieve outdated pricing sheets, archived HR records and obsolete technical specifications.

The company launched a six-week remediation project using Microsoft Purview and SharePoint access reviews. Administrators first identified overshared locations through the Microsoft 365 admin center and SharePoint Admin Center reports.

The most important operational step was reviewing external and broad internal sharing. Administrators checked SharePoint Admin Center -> Policies -> Sharing and reduced default link permissions from “Anyone” to “People in your organization.” High-risk project libraries were moved to restricted Microsoft 365 groups.

The team also implemented sensitivity labels that automatically applied encryption and access restrictions to procurement contracts and employee records. Auto-labeling policies in Microsoft Purview targeted files containing national identification numbers and payroll data.

The result was immediate. Open-access document exposure dropped by 74%, and employees reported faster search accuracy because outdated duplicate files were removed from indexing scope. Operationally, the company reduced manual access-review effort by roughly 25 hours per month while significantly lowering AI-related data leakage exposure under EU AI Act governance requirements.

AI usage monitoring requires real governance metrics

Many organisations claim to govern AI usage but measure nothing beyond license counts. EU AI Act governance becomes credible only when operations teams track adoption, exceptions and policy violations with measurable metrics.

A Danish retail distributor with 95 staff introduced monthly AI governance reporting after discovering that employees regularly pasted supplier contracts into public AI chatbots. IT initially blocked several services, but staff bypassed restrictions using personal devices.

The company shifted from pure restriction to monitored governance. Operations managers worked with IT to define measurable indicators:

  1. Approved versus unapproved AI services
  2. Number of AI-related incidents
  3. Sensitivity label violations
  4. External sharing events
  5. AI procurement requests
  6. User training completion rates

Microsoft Purview Insider Risk Management and audit logs provided operational visibility. Administrators reviewed activity through the Microsoft Purview portal under Solutions -> Audit and configured retention policies for investigation history.

Power BI dashboards connected to Microsoft 365 usage reports gave department managers visibility into collaboration trends and risky sharing patterns. For example, one business unit generated 63% of all external-sharing events despite representing only 18% of staff.

The EU AI Act reporting structure produced measurable improvements within four months. Unapproved AI usage incidents dropped from 27 monthly events to 9. Training completion increased from 41% to 92% after department-specific reporting exposed compliance gaps. Those metrics also improved executive reporting because leadership received operational KPIs instead of abstract policy statements.

EU AI Act transparency obligations affect internal workflows

EU AI Act transparency expectations increasingly affect internal employee workflows, especially where AI-generated outputs influence customer communication, recruitment or operational decisions.

A Netherlands-based business services company used AI-generated proposal drafts and customer email summaries inside Microsoft Teams. Employees often forwarded AI-produced content directly to customers without review. During a quality audit, management identified factual errors in 14% of sampled AI-generated documents.

The company implemented mandatory human-review workflows using Microsoft Power Automate and Teams approvals. AI-generated proposal drafts stored in SharePoint required manager sign-off before external release.

The operational workflow started in a SharePoint document library configured with content approval enabled through Library Settings -> Versioning settings -> Require content approval for submitted items. When a file received the “AI Draft” metadata label, Power Automate triggered a review request in Teams.

Employees also received mandatory disclaimer templates for AI-assisted customer communication. The organisation maintained these templates centrally within SharePoint document content types to ensure consistency.

The outcome was measurable within one quarter. Customer-facing document correction rates fell from 14% to 4%, while approval turnaround averaged under 3 hours because reviews occurred directly inside Teams. More importantly, the company created auditable proof that humans reviewed AI-generated outputs before operational use in line with EU AI Act transparency expectations.

Supplier governance is now an operations responsibility

Operations leaders increasingly manage AI supplier risk because legal and procurement teams rarely understand technical deployment details. EU AI Act obligations make vendor governance more operational than contractual.

A Norwegian construction company with 160 employees used six separate AI-enabled SaaS platforms across HR, document processing and customer support. During a supplier review, operations managers discovered that two vendors processed data outside the EEA without clear subprocessors documentation.

The company established a standard AI supplier review process using Microsoft Lists and Teams. Every supplier assessment included:

  • EEA data residency confirmation
  • Subprocessor disclosure review
  • Security certification verification
  • Human oversight procedures
  • Data retention policy checks
  • Incident notification timelines

Supporting contracts and security documentation were stored in a restricted SharePoint library with access limited through Microsoft 365 group membership. Administrators reviewed permissions using SharePoint Site Permissions -> Advanced permission settings.

The organisation also introduced annual supplier reassessments through recurring Power Automate reminders. Previously, vendor reviews happened only during procurement.

Operationally, supplier reassessment completion rates increased from below 30% to 100% within one reporting cycle. More importantly, the company identified three contracts requiring updated data-processing terms before renewal. That process significantly reduced unmanaged vendor exposure while improving EU AI Act audit readiness.

Employee training must shift from policy to operational behavior

Many AI governance programs fail because employee training focuses on legal theory rather than daily operational decisions. Staff need practical guidance tied directly to Microsoft 365 workflows.

A 70-person accounting company in Germany initially distributed a PDF AI policy through email. After six weeks, fewer than half of employees had read the document, and risky AI usage patterns continued.

The company replaced passive communication with scenario-based operational training delivered through Microsoft Viva Learning and Teams. Employees completed short modules covering:

  • Safe AI prompt handling
  • Customer-data restrictions
  • Approved AI tools
  • SharePoint sharing rules
  • Human review obligations

Operations managers also embedded governance reminders directly into daily workflows. Teams channel tabs linked to approved AI guidance, while SharePoint pages displayed contextual usage instructions for finance and HR teams.

A particularly effective control involved conditional access and sensitivity labels. Files marked “Confidential” displayed visual prompts warning users against entering regulated data into unapproved AI systems.

Training completion and acknowledgement tracking occurred through Microsoft Forms and Power Automate notifications. Department heads received escalation alerts for overdue participation.

The measurable impact was strong. Reported risky AI behavior incidents fell by 61% within five months, while employee confidence scores regarding approved AI usage increased from 46% to 81% in internal surveys. That operational awareness supports every other EU AI Act governance control discussed in this article.

Building a realistic 12-month EU AI Act roadmap

Operations leaders often overcomplicate AI governance by trying to implement enterprise-scale controls immediately. Mid-market organisations achieve better results through phased operational roadmaps aligned with Microsoft 365 capabilities they already own.

A 110-person industrial supplier in Belgium built a 12-month AI governance roadmap around three practical phases. During the first quarter, the company focused on visibility by inventorying AI tools and tightening SharePoint sharing controls. The second phase implemented documentation, supplier reviews and employee training. The final phase introduced reporting dashboards and automated monitoring.

The roadmap relied heavily on existing Microsoft 365 licensing rather than new platforms. SharePoint handled governance documentation, Teams managed approvals, Power Automate coordinated workflows and Microsoft Purview supported classification and audit capabilities.

The most important operational lesson was sequencing. The company first cleaned permissions and data access before expanding AI adoption. This prevented employees from exposing legacy overshared content through AI search and summarisation tools.

Executive reporting used quarterly KPIs including approved AI tools, governance exceptions, training completion, audit findings and external-sharing incidents. Leadership meetings reviewed governance metrics alongside operational productivity indicators.

EU AI Act governance succeeds when operations teams combine Microsoft 365 controls, measurable reporting and supplier oversight into one repeatable workflow. Mid-market companies typically see 20-35% lower compliance administration effort after the first year.

After 12 months, the organisation reduced AI-related compliance incidents by 58%, lowered manual governance administration effort by approximately 30 hours monthly and accelerated approved AI adoption across customer support and operations planning teams. That balance between innovation and operational control is ultimately what EU AI Act governance requires.

Further reading

Related KSJ articles

Official resources

Contact KSJ about AI governance update

How KSJ can help

See pricing & book a discovery call

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top