The EU AI act is now enforceable. Is your business ready? What changed in agentic AI this week (3 - 9 August 2026)
Artificial intelligence is already changing how organisations communicate, make decisions and get work done. But as AI moves from isolated experiments into everyday operations, businesses need more than access to powerful technology.
Jeannie McGilllivray
8 min
AI governance
Artificial intelligence is already changing how organisations communicate, make decisions and get work done.
But as AI moves from isolated experiments into everyday operations, businesses need more than access to powerful technology. They need to understand where AI is being used, who is responsible for it, what information it can access and whether its decisions can be explained.
That is the challenge the EU AI Act has been created to address.
The Act entered into force on 1 August 2024 and became broadly applicable on 2 August 2026, although some requirements took effect earlier and others remain subject to transitional arrangements. Enforcement powers are now available to the European AI Office and national authorities.
For businesses, the question is no longer simply:
How can we use AI?
It is now:
How can we use AI responsibly, transparently and with the evidence to demonstrate that we are doing so?
The EU AI Act reaches beyond the EU
The legislation matters to more than businesses headquartered in Europe.
It applies to organisations deploying AI systems within the EU and can also apply to providers and deployers based outside the EU where the output of an AI system is used within the Union. This means UK organisations may still fall within its scope when serving European customers, employing people in the EU or using AI to produce outputs that affect European operations.
The Act follows a risk-based approach. The obligations placed on an organisation depend on factors including:
how an AI system is used;
the potential effect on individuals;
whether the organisation is providing or deploying the system;
whether the use falls into a prohibited, high-risk, transparency or lower-risk category.
Most everyday business uses of AI will not necessarily be classified as high-risk. However, that does not remove the need for visibility, governance, training and responsible oversight.
Compliance starts with knowing where AI is being used
For many organisations, the greatest immediate risk is not deliberate misuse of AI. It is uncontrolled use.
Employees may be using several AI assistants, automation tools and embedded AI features across different departments. Sensitive information may be copied into systems without an agreed policy. AI-generated outputs may influence decisions without being recorded. Actions may be completed without anyone being able to reconstruct what information was used or who approved the result.
When AI adoption develops in this fragmented way, governance becomes extremely difficult.
A business cannot effectively control what it cannot see.
Before an organisation can assess risk, apply policies or demonstrate compliance, it needs a clear operational view of:
which AI systems are in use;
who is using them;
what purpose they are being used for;
what information they can access;
what actions they are permitted to take;
where human review is required;
how activity and decisions are recorded.
This is where Autm provides an important foundation.
How Autm supports EU AI Act compliance
Autm is an operational intelligence platform that connects with the tools a business already uses, including email, calendars, meetings, documents, project systems and CRM platforms.
It brings the information and activity flowing through those systems into a governed operational layer, allowing organisations to introduce AI without losing control of context, permissions or accountability.
Rather than adding another disconnected AI application, Autm helps businesses create a controlled environment in which AI-supported work can be understood, supervised and audited.
1. Visibility over AI-supported work
Responsible AI adoption requires organisations to understand where and how AI is influencing their operations.
Autm connects activity across business systems and workspaces, helping organisations maintain a clearer view of the information, conversations, actions and workflows being processed.
This makes it easier to establish an AI inventory, identify use cases and understand which teams, processes and data sources are involved.
That visibility supports the first essential step in compliance: knowing what needs to be governed.
2. Human oversight and control
For deployers of high-risk AI systems, the Act places particular emphasis on appropriate human oversight. Deployers must follow instructions for use, monitor system operation, respond to identified risks and assign oversight to people with the necessary competence and authority.
Human oversight is also a valuable principle for lower-risk business AI.
Autm allows organisations to design workflows in which AI can prepare information, identify actions, make recommendations or complete permitted tasks while retaining appropriate points of human review.
Permissions and approval stages can be aligned with the significance of the action. Routine administrative work may be automated, while sensitive decisions remain subject to explicit human control.
The objective is not to remove people from the process. It is to ensure that people remain in control of the parts of the process that matter.
3. Traceability and auditability
One of the most important questions in governed AI is:
Can we show what happened?
Autm maintains the relationship between source information, organisational context, actions, workflows and outcomes. This helps create an auditable record of how work progressed and why particular actions were taken.
For organisations using AI in material business processes, this can support:
internal governance reviews;
risk assessments;
investigation of errors or unexpected outcomes;
evidence of human involvement;
accountability for approvals and decisions;
responses to customers, regulators or auditors.
The EU AI Act imposes specific logging and record-retention obligations in relation to certain high-risk systems. For example, deployers may be required to retain logs generated under their control for an appropriate period, generally at least six months.
Autm’s emphasis on traceability gives organisations an operational structure through which relevant evidence can be retained and accessed.
4. Data access and permission controls
AI governance is inseparable from data governance.
An AI system should not be able to access information simply because that information exists somewhere within the business. Access needs to reflect the user, team, purpose and sensitivity of the data involved.
Autm uses workspaces, permissions, visibility preferences and access controls to help organisations determine what information can be used, by whom and in which context.
This supports principles such as:
purpose limitation;
data minimisation;
appropriate confidentiality;
separation between teams, clients or projects;
controlled access to sensitive business knowledge.
It also reduces the risk of an AI assistant exposing information to someone who would not otherwise have permission to see it.
5. Transparency around AI interactions and outputs
Article 50 of the EU AI Act introduces transparency obligations for certain AI systems and AI-generated content. These include circumstances in which people must be informed that they are interacting with AI or that content has been artificially generated or manipulated. Many of these transparency requirements became applicable on 2 August 2026.
Autm can help organisations build transparency into operational processes rather than treating it as an afterthought.
Workflows can be designed to identify AI-supported actions, retain the origin of generated content and require appropriate review or disclosure before material is sent, published or used.
This gives businesses greater control over when AI output enters the outside world and who takes responsibility for it.
6. Consistent policies across the organisation
A written AI policy is valuable, but a document alone does not control day-to-day behaviour.
Effective governance requires policies to be reflected in the systems through which people actually work.
Through governed workspaces, permissions, templates and workflows, Autm helps translate organisational policies into repeatable operational controls.
For example, an organisation can establish:
which tools are approved;
which categories of data may be used;
where human approval is mandatory;
which actions may be automated;
when AI-generated content must be reviewed;
how exceptions or incidents should be escalated;
what evidence must be retained.
This moves AI governance from intention into practice.
7. Supporting AI literacy
Article 4 of the Act requires providers and deployers to take measures that support the development of AI literacy among employees and others operating AI systems on their behalf.
The European Commission recommends that organisations consider what AI they use, their role as provider or deployer, the risks associated with their systems and the knowledge employees need to use those systems responsibly.
Technology cannot replace training, but it can reinforce it.
Autm helps organisations give employees a consistent, governed way to work with AI. Guidance, processes and approval requirements can be embedded into workflows, reducing reliance on individuals remembering every element of a policy independently.
It also provides organisations with greater visibility into how AI is being adopted, helping them identify where additional support or training may be needed.
From AI experimentation to governed adoption
Many businesses currently face a difficult choice.
They can restrict AI use because of the risks, leaving employees and competitors to move ahead without them.
Or they can allow widespread adoption and hope that informal policies will be enough.
Neither approach is sustainable.
The better answer is governed adoption: giving people access to useful AI capabilities within an environment designed around permissions, transparency, human accountability and evidence.
That is the model Autm has been built to support.
Autm allows organisations to connect their existing systems, introduce operational AI and create the controls required to use it responsibly. It helps businesses understand what their AI is doing, supervise the actions it takes and retain the context needed to demonstrate responsible practice.
Does Autm automatically make a business compliant?
No technology platform can guarantee EU AI Act compliance on its own.
An organisation’s obligations depend on the AI systems it uses, the purposes for which they are used, the organisation’s legal role and the risks created for individuals.
Businesses may still require legal advice, formal risk classification, staff training, impact assessments, documentation and specific controls for high-risk or regulated use cases.
What Autm provides is the operational infrastructure that makes compliance far more achievable.
It helps organisations put the central principles of trustworthy AI into everyday practice:
visibility;
controlled access;
human oversight;
transparency;
traceability;
accountability;
evidence.
Compliance should be designed in, not added later
The EU AI Act should not be seen simply as another administrative burden.
Used well, it provides a framework for introducing AI in a way that employees, customers, boards and regulators can trust.
Organisations that establish strong governance now will be better positioned to adopt more capable AI in the future. They will be able to move faster because they understand their data, their systems, their responsibilities and their controls.
Autm has been built to help businesses make that transition: from disconnected AI tools and hidden operational risk to coordinated, governed and accountable intelligence.
Your business has systems. Autm gives them intelligence — with the control and evidence responsible AI adoption requires.
This article provides general information and does not constitute legal advice. Organisations should obtain advice appropriate to their circumstances and assess each AI system and use case individually.
