How to comply with EU AI Act

The European Union has adopted the AI Act (Regulation (EU) 2024/1689), a comprehensive regulatory framework governing the development, deployment, and use of artificial intelligence. As a regulation, the AI Act applies directly across the EU and introduces a common set of requirements aimed at ensuring that AI systems are safe, trustworthy, and respectful of fundamental rights.

What does the AI Act mean for organizations using AI?

Organizations that use AI systems such as Microsoft Copilot, ChatGPT, Claude, or other generative or decision-support tools typically fall under the role of deployers according to the AI Act.

If an AI system processes personal data – which is often the case – organizations must comply with both the GDPR and the AI Act. This means operating under two regulatory regimes at the same time:

  • Under the GDPR, the organization acts as a data controller and must ensure lawful processing, transparency, data minimization, and appropriate security measures.
  • Under the AI Act, the organization acts as a deployer and must meet a set of obligations related to AI risk management, governance, oversight, and accountability.

While there is some overlap between the two frameworks, the AI Act goes beyond data protection and introduces requirements related to fundamental rights, system behavior, and lifecycle management of AI systems.

Key obligations under the AI Act for deployers

The AI Act introduces a risk-based approach. Among other things, organizations must ensure that:

  • AI systems are classified according to risk
  • high-risk AI systems are subject to enhanced governance, testing, traceability, and documentation requirements
  • AI systems are monitored and followed up after deployment (post-market monitoring)
  • human oversight is implemented where required
  • potential impacts on fundamental rights are assessed – not limited to privacy alone
  • incidents, malfunctions, and adverse effects are handled systematically
  • roles and responsibilities related to AI governance are clearly defined

Documenting compliance in practice

To comply with the AI Act, organizations must be able to demonstrate compliance in a structured, consistent, and auditable way. This is where Microsoft Purview Compliance Manager can be used as a practical supporting framework.

Within Compliance Manager, Microsoft provides a premium template called the EU Artificial Intelligence Act. This template translates the requirements of the AI Act into 93 organizational and technical improvement actions.

These improvement actions are derived directly from the regulation and mapped to relevant chapters and articles across the AI Act.

The template does not automatically make an organization compliant, nor does it replace the legal and organizational assessments that must be performed. Instead, it provides a structured way to identify, prioritize, implement, and document measures related to the use of AI systems.

The template is not tied to a specific AI service, but it is particularly relevant for organizations using AI capabilities within the Microsoft 365 ecosystem. This includes M365 Copilot, Copilot Chat, and other generative AI solutions that use organizational data stored in SharePoint, OneDrive, and Exchange.

To use the EU AI Act template in Compliance Manager, at least one A5 or E5 Compliance Suite license is required, or alternatively an A5 or E5 license.

Example 1 – Article 12: Record-keeping and logging

Article 12 of the AI Act sets requirements for record-keeping and logging for high-risk AI systems. The objective is to ensure traceability, auditability, and the ability to perform effective investigations if incidents or failures occur.

Several improvement actions in Compliance Manager are directly linked to Article 12.1.

These improvement actions focus on establishing comprehensive logging and traceability across systems involved in AI usage. By automatically collecting logs from sources such as firewalls, proxies, and cloud services, organizations gain a consolidated view of activity and events related to AI usage.

In addition, cloud activity logs and audit logs provide detailed audit trails for changes to cloud resources and actions performed by users and administrators. This makes it possible to determine who did what, when it happened, and at what level. Together, these capabilities provide a strong and auditable foundation for meeting the record-keeping and logging requirements of Article 12.

Example 2 – Article 14: Human oversight

Article 14 introduces requirements for human oversight of high-risk AI systems. The goal is to ensure that AI systems do not operate without meaningful human control and the ability to intervene when necessary.

Several improvement actions in Compliance Manager are mapped to Article 14.4.

These actions collectively support governance and human control over AI usage. By classifying data using sensitivity labels and restricting AI access to data through data loss prevention (DLP) policies, organizations can significantly reduce the risk of AI systems accessing or disclosing information they should not.

In addition, reporting and analytics capabilities in Microsoft Purview provide visibility into how AI is actually being used, including whether sensitive data appears in prompts or is used in unintended ways. These measures make it possible to monitor AI usage, understand emerging risks, and intervene when required, in line with the human oversight requirements of the AI Act.

Note that improvement actions in Compliance Manager contribute different point values. These scores are intended to support prioritization and risk-based decision-making, not to replace legal judgment.

Assessing and tracking compliance

Once the EU AI Act template has been enabled and improvement actions have been implemented, organizations can run assessments in Compliance Manager to evaluate their current level of compliance.

The assessment score is divided into two parts: one part reflects improvement actions that Microsoft has implemented as the service provider. The other part reflects actions that the organization itself is responsible for implementing.

If we select “Your improvement actions”, we can see what we need to do. Ouch, only 2 % completed!

Used correctly, Microsoft Purview provides a practical and structured foundation for translating the AI Act’s legal requirements into concrete technical and organizational measures. It enables organizations to document compliance, track progress over time, manage risk, and support a responsible and trustworthy use of artificial intelligence.