What the EU AI Act means for businesses using ChatGPT, Copilot or other third-party Generative AI tools in the workplace.

01

The product name is not the compliance test

A company using ChatGPT, Microsoft Copilot or another third-party Generative AI service may be a deployer of an AI system, but the exact analysis depends on the system and the way it is used. The organisation also needs to consider obligations outside the AI Act, including data protection, confidentiality and sector-specific rules.

02

Four questions to ask

  • What tasks are employees using the tool for?
  • What personal, customer, confidential or commercially sensitive data can enter it?
  • Are outputs used only as assistance or do they influence decisions affecting people?
  • Has the organisation configured, integrated or repurposed the system in a way that could change its regulatory role?
03

Everyday GenAI still needs governance

Even a lower-impact use can produce incorrect outputs, leak sensitive information through poor prompting practices or create intellectual property and confidentiality issues. Approved tool lists, AI literacy, clear data rules and human verification are practical controls regardless of whether the use is high-risk under the AI Act.

04

When to perform a deeper assessment

Escalate when Generative AI is embedded into customer-facing processes, used to make or materially support consequential decisions, receives sensitive or large-scale personal data, or is integrated into a product or service your organisation supplies. Those facts can change both the risk and the legal analysis.

05

Blanche perspective

Separate the question 'may employees use this tool?' from 'may we use it for this purpose?'. Tool approval is only one layer. Good governance also controls the data, task and level of human reliance for each important use case.

S

Sources

Primary and authoritative sources used for this Insight.

  1. European Commission: AI Act
  2. Irish DPC: AI, large language models and data protection