Trusted AI

The AI Act: key steps to ensure your company's compliance

The AI Act enters its final adoption phase this August—are you ready?

⚡️ TLDR

  • Key deadline (August 2026): The European AI Act is entering its final implementation phase to regulate the deployment of AI within organizations.
  • Prioritizing fundamental rights: More than just a technical constraint, the regulation aims to protect privacy, dignity, freedom of expression, and non-discrimination.
  • Defining AI: Based on the inference capability (a system's ability to predict or make decisions by going beyond fixed programmed rules).
  • Regulatory overlap: The AI Act does not replace existing rules: it complements GDPR, DORA (finance), and cybersecurity requirements.
  • Risk-based approach: AI use cases are classified into 4 risk categories, which determine the level of compliance required.

The massive adoption of artificial intelligence within organizations is raising unprecedented legal and operational questions.

Faced with this challenge, the new European AI Act establishes a strict yet structuring framework that will enter its final phase of implementation starting this August 2026.

To help you gain clarity, Craft AI has teamed up with La Robe Numérique for a webinar!

AI Act timeline, obligations, methods for auditing your use cases… Discover the key points covered by Xavier Trigano and Oriana Labruyère during this discussion right now.

1. Understanding the Logic of the AI Act: Fundamental Rights and Risk-Based Approach

The AI Act is not just a text about technical constraints or financial penalties. It is a political compromise, negotiated over several years, whose absolute priority is the preservation of the fundamental rights of European Union citizens (dignity, non-discrimination, privacy, freedom of expression).

The regulation defines AI by a precise technical criterion: its inference capability. This is a system's ability to deduce a result (prediction, recommendation, decision) from data, going beyond fixed rules strictly programmed by humans.

While the practical boundary between traditional software and AI sometimes remains blurred, the European Commission will soon publish guidelines to refine this distinction.

“The AI Act does not replace any existing regulations. It complements the GDPR, the DORA directive for the financial sector, and sector-specific cybersecurity rules. It is a cumulative approach: an AI must comply with the AI Act AND the GDPR.”

2. The AI Act Risk Pyramid

The text classifies AI applications into four major risk categories, leading to graduated obligations:

Niveau de Risque Exemples d'applications Statut & Obligations
🔴 Inacceptable Notation sociale, scoring biométrique politique/religieux, reconnaissance des émotions au travail/école, moissonnage d'images faciales. Interdit
En vigueur depuis le 2 février 2025.
🟠 Haut Risque Systèmes de tri de CV/recrutement, évaluation du crédit bancaire (credit scoring), infrastructures critiques, éducation. Sous conditions
Autorisé sous conditions strictes : supervision humaine, journalisation, marquage CE.
🟡 Limité Chatbots, générateurs de contenus (images, textes). Transparence
Obligation de transparence (mention explicite "Généré par IA", watermark).
🟢 Faible / Minime Outils de productivité de base, filtres anti-spam. Recommandations
Pas d'obligation légale spécifique, mais des recommandations de bonnes pratiques.

The specific case of GPAI (General Purpose AI models): Large language models (LLMs) such as Mistral AI, OpenAI, or Claude fall under a specific regime. Subject to phased implementation, they require in-depth impact assessments to evaluate risks depending on whether they are used raw, fine-tuned, or integrated via API.

3. The "RADAR" Method for Auditing Use Cases

Developed by Xavier Trigano, the RADAR method allows any organization to manage its compliance iteratively:

  • R – Review : Exhaustively map all of the company's use cases (internal tools for employees and commercialized solutions).
  • A – Assign roles : Identify whether the organization is acting as a model provider, AI system provider, integrator, or deployer (end-user). A single company may hold multiple roles.
  • D – Determine the risk : Assess the risk level based on the use case type and its purpose (Unacceptable? High risk? Limited? Low?).
  • A – Apply measures : Implement the technical and organizational actions required by the identified risk level.
  • R – Record documentation : Compile the register and evidence of compliance (similar to the GDPR accountability principle).

"AI by Design" Focus - The example of automated CV screening: An HR tool that autonomously rejects or accepts candidates is classified as "High Risk," entailing significant compliance costs. The RADAR method instead recommends a "by design" approach: modify the tool's features to function as a decision-support system (extracting key skills from the CV while leaving the final decision to a human recruiter). The tool provides the same business value but shifts to "limited risk," drastically reducing legal constraints.

4. FAQ: Shadow IT, GDPR, and Sovereignty

How can companies combat Shadow AI?

Outright bans do not work. To manage how employees use LLMs, the response must be cross-functional:

  • Define a catalog of authorized use cases based on secure tools provided by the company.
  • Use Data Loss Prevention (DLP) technology to block the uploading of sensitive data to third-party LLMs.
  • Update the IT policy and internal regulations.

Does using LLMs (ChatGPT, Claude, etc.) violate the GDPR?

It is not the tool itself that constitutes a violation, but the purpose of its use. Rewriting a marketing campaign using Claude poses no GDPR risk. However, uploading the company's entire HR age-pyramid file without precautions constitutes a serious breach. 

Sovereign alternatives (hosted on-premises or on French/European clouds) can mitigate risks associated with the U.S. Cloud Act while ensuring equivalent efficiency.

How can I guide my teams in their use of AI? 

The AI Act mandates training for all users within an organization. Since AI can make mistakes or "hallucinate," only the critical thinking of a trained human can cover this residual risk and ensure effective quality control.

5. Conclusion: The AI Act, a driver of trust and competitiveness

The AI Act should not be seen as a barrier to innovation, but as a framework for trust. 

By integrating compliance from the design phase of projects, AI becomes a sustainable driver of economic performance, social acceptance, and sovereignty.

Looking to develop your own custom AI agent that complies with the AI Act? Contact our team. 

And access the replay of this webinar now!