Who is actually concerned
The regulation does not only target model providers. Any company that uses an AI system is in scope as a user, with lighter obligations than providers, but real ones: know what you use, inform the people concerned, train your teams.
A services company using AI assistants, a chatbot or automations is therefore covered. The good news: for the vast majority of these uses, the obligations come down to transparency and documented control; there are no certification files to assemble. The point is to be able to show, in writing, what you use and how.
The risk tiers, explained simply
The regulation classifies systems by level of risk. At the top, prohibited practices such as manipulation and social scoring. Then high-risk systems, subject to heavy obligations: they touch on recruitment, credit and other sensitive areas, and remain rare in a services company.
Next come systems with a transparency duty: a chatbot must say it is an AI, generated content must be identifiable as such. Finally, minimal risk: the majority of productivity tools, with no particular obligation beyond common sense.
The useful exercise for a leadership team is to place your own uses in these tiers, with no need to learn the text. That classification fits on one page and determines everything else.
The register of AI uses
The register of uses is the foundation. For each AI use: the tool, the purpose, the data it touches, the people who use it, the provider and its contract. Include the unofficial uses: they are often the riskiest, precisely because they escape any framework.
This register serves beyond compliance: it answers the questions of clients and larger buyers, who increasingly ask how their data is handled. A written, up-to-date answer becomes a selling point.
Keep it alive: one new use, one new line. A register dated eighteen months ago is barely better than no register at all. Give its upkeep to the internal AI lead, and review it every time a new tool enters the company: the update takes minutes, the rebuild takes weeks.
The training obligation
The most immediate point: teams who use AI must be trained in its limits and its rules of use, with a deadline in August 2026. It is a legal obligation in its own right, and it applies to ordinary companies just as much as to technology firms.
Useful training starts from the company's real cases: which tools, which data may go into them, what to check before reusing an output. And it is documented: who was trained, when, on what content.
We deliver this training and we document the record. The evidence file counts as much as the training itself: it is what you produce the day the question arrives. Plan short sessions, team by team, on the tools actually used: more effective than one general day for everyone.
Where to start this quarter
This quarter, three steps are enough. One: the inventory of uses, official and unofficial, to build the register. Two: appointing an internal AI lead, which simplifies everything even where nothing requires it. Three: the transparency notices where they are missing, starting with the chatbot.
Then plan the team training ahead of the August 2026 deadline, starting with the people who handle client data. For a services company, the essentials are handled in a few weeks of structured work.
The Strategic Diagnostic structures this start: a map of your uses, your risks and your priorities, and a dated action plan. €3,500, deducted if you continue with us. You leave with a document you can present as it stands to your board, your clients or your insurer.
