Ask a mid-sized company how many AI systems it runs and the answer is usually a small number. There is the chatbot on the website, perhaps a forecasting model in finance, maybe a pilot project in customer service. Ask the same question more carefully, department by department and supplier by supplier, and the number tends to grow quickly. The recruitment platform ranks candidates. The CRM scores leads. The fraud tool flags transactions. None of these were bought as “AI projects”, yet all of them contain models making or shaping decisions.
This gap between perceived and actual AI use has become more than an academic curiosity. Under the European Union’s AI Act, obligations do not fall only on the companies that build AI systems. They also apply to organisations that deploy them, a category that can include many businesses simply using software with machine learning inside. A UK company selling into the EU, or whose AI systems produce output that is used in the EU, can find itself within scope without ever having written a line of model code. The regulation takes a risk-based approach, so a spam filter and a system that screens job applicants are treated very differently.
The practical starting point, then, is not legal interpretation but inventory. Before anyone can decide whether a system is high-risk, someone has to know it exists. That sounds obvious, but in most organisations AI arrives quietly, through a feature update in a SaaS product or a new module switched on by a team lead. Procurement rarely asks whether a tool uses automated decision-making. IT may not be told. The result is what some practitioners now call shadow AI: models operating inside the business with nobody formally responsible for them.
Building that inventory is tedious work, and it rarely fits neatly into one department. It needs input from procurement, HR, legal, data teams and the business units themselves. For each system, the useful questions are simple enough: what does it decide or recommend, whose lives does that affect, where does its data come from, and who at the supplier can explain how it behaves. Organisations that have started down this road often turn to specialist support on EU AI Act readiness, largely because classifying systems against the regulation’s risk categories requires both technical and regulatory judgement, and few internal teams have both.
Supplier contracts are the next pressure point. If a vendor’s model is doing the heavy lifting, the deploying company still carries duties around human oversight, record keeping and, in some cases, informing the people affected. That depends on getting documentation, logs and explanations from the supplier, which many standard contracts simply do not provide for. Renegotiating those terms is slow, which is one reason why waiting for enforcement deadlines to arrive before starting is a poor strategy, even though Brussels has reopened parts of the timetable.
There is an upside hidden in all this. Companies that map their AI use properly tend to discover duplicated tools, forgotten licences and models trained on data nobody would sign off today. The exercise that begins as compliance often ends as a clearer picture of how decisions are really being made inside the business, which is useful to have regardless of what any regulator asks.
Read also One Day in Athens from Piraeus: Making a Cruise Stop Count