THE KEY IDEA

An approved tool is not approval for every use. Assess the purpose, the data, the affected people and the decision the system supports.

Find the AI already in the business

An organisation may have an AI policy and still lack a clear picture of where AI is used. A writing assistant, recruitment feature, fraud detection service and customer support tool can enter through different purchasing routes. Employees may also use publicly available tools without recognising that their activity raises a business question.

Start with an inventory of use cases rather than a catalogue of brands. Record the business purpose, owner, users, supplier, information entered and decisions influenced. Include AI embedded in existing software. The inventory should make it possible to ask who is responsible when the output is unreliable or the use changes.

Do not assume that the same review fits every application. Drafting an internal meeting agenda and ranking job applicants have different consequences. This is why a useful approval process focuses on the application and the people affected.

Separate legal applicability from good governance

Determine which requirements apply to the organisation’s role, location and use case. An AI-specific rule may sit alongside existing privacy, employment, consumer protection or confidentiality duties. Obtain a documented legal interpretation where the classification or territorial scope is uncertain.

The European Commission’s AI literacy guidance states that Article 4 obligations began applying on 2 February 2025. It describes a contextual approach to the knowledge and understanding needed by relevant staff. Do not treat a generic course as proof that every applicable obligation has been met.

This article proposes operational questions rather than a universal legal compliance checklist. AI rules and implementation arrangements can change; confirm the current requirements for the intended deployment before using a regulatory timeline as an approval decision.

Reference: European Commission AI literacy guidance.

Make human review meaningful

A person clicking “approve” does not necessarily provide effective oversight. Ask what that person can see, what expertise they need and whether they have time and authority to challenge the output. If the reviewer cannot identify a plausible error, adding a sign-off may only create the appearance of control.

Define the boundary of permitted use. For example, a drafting assistant may help prepare an initial summary while a qualified reviewer verifies the underlying sources before the document is relied on. Specify information that must not be entered, required checks and situations in which the tool must not be used.

Test failure cases deliberately. Examine an incomplete input, a misleading source or an unusual case relevant to the business. Record what the system does, how the reviewer responds and whether the fallback process works. Supplier assurances can inform the review, but should not substitute for understanding the organisation’s own use.

Treat change as a new risk signal

AI-enabled services may change through supplier updates, new integrations or expanded access. A review performed at purchase can become disconnected from the current use. Agree which changes require reassessment and how the owner learns about them.

Monitor issues proportionately: incorrect outputs that escape review, inappropriate information sharing, unexplained decision patterns or employees using the tool outside its approved purpose. Collect only the information needed for the monitoring task and manage its access and retention.

Finally, establish a practical stop route. Who can suspend the use case? What work continues manually? Who investigates and decides whether to restart? The programme becomes credible when it can answer these questions before an incident, with evidence that staff understand their responsibilities. The aim is responsible use supported by clear boundaries, not an assumption that technology can absorb accountability.

Put it into practice

  1. Inventory five actual AI uses, including embedded software features.
  2. Assign a business owner and document permitted and excluded purposes.
  3. Test a realistic failure case and the reviewer’s response.
  4. Confirm the escalation, suspension and reassessment process.

Sources and scope

European Commission — AI Literacy: Questions & Answers

Compliance House’s practical analysis, with illustrative scenarios. Framework references are identified above. Apply the approach to your organisation and confirm the legal requirements relevant to its jurisdictions and activities. References checked 15 September 2026.