Time to wake up to AI accountability

AI is no longer something that sits in a research lab or a technology department... it is already part of the daily workflow

SHARE

There is a quiet but dangerous assumption spreading through many boardrooms: that if a company is not building or using a high-risk AI system, the law has little to say to it. It is an attractive thought, especially for businesses that use AI only to draft emails, support customer service, generate marketing content, or speed up internal work. But it is also wrong.

The EU AI Act may reserve its toughest obligations for systems used in areas such as recruitment, credit, education, law enforcement and access to essential services. Ordinary businesses are not being asked to carry the same burden as organisations deploying high-risk systems. Even so, they are not being given a free pass. The message is more practical than dramatic: know what AI tools you use, explain them when people are affected, keep humans in charge, train your staff, and keep evidence that your suppliers are acting responsibly.

That is not red tape for its own sake. It is the basic hygiene of modern business.

This matters because AI is no longer something that sits in a research lab or a technology department. It is already part of the daily workflow. A shop may use a chatbot to deal with customer questions. A law firm may use a writing assistant to prepare a first draft. A marketing team may generate images for a campaign. An HR department may use software to organise information about staff or applicants. None of these organisations may think of itself as an "AI business", yet from the customer's or employee's point of view, the impact can be very real.

A person may be speaking to a machine without knowing it. They may be reading content that appears human-made but isn't. They may be affected by a recommendation that began as a computer-generated suggestion and ended as a business decision. That is why the "don't trick people" rule is so important. It is not a slogan dreamed up by lawyers. It is the moral centre of the new framework. When AI is used in a way that touches people, people deserve to know.

The first duty is also the most basic: keep an internal inventory. Every business should know which AI tools it uses, who uses them, what they are used for, what data they process, and what risk category they fall into. It may sound like a dull administrative exercise, but it is the foundation on which everything else rests. Without an inventory, a company cannot honestly say it is compliant, because it does not even know what it has to control. Organisations might not have realised this, but "shadow AI" is one of their biggest risks: staff quietly using public tools, browser extensions, or built-in software features without legal, IT, or management oversight. This is how a harmless productivity shortcut can turn into a privacy, copyright, or reputational problem. That is why businesses need a living register, not a dusty spreadsheet created once and forgotten.

The second duty is transparency. Businesses must tell people when they are interacting with an AI system, when content is AI-generated, and when AI is used to make or support decisions about them. This is especially important because polished digital communication has become normal. A customer may not immediately realise that the helpful chat window on a website is not operated by a person. A reader may not know that an image in an advert was created artificially. An employee may not realise that a manager's decision was shaped by an automated recommendation. In each case, the issue is not whether AI was useful. The issue is whether people were treated honestly. Transparency does not need to be dramatic or frightening. It can be a clear notice, a simple label, a short explanation at the point of use, or a policy written in language people can actually understand. But it must be visible, timely and honest. The worst approach is to bury the truth in a long privacy notice and hope nobody reads it.

The third duty is human oversight. Even where the law does not impose the stricter rules reserved for high-risk systems, businesses should not allow AI to become the final decision-maker in matters that affect people. A human being must remain responsible, and that responsibility must mean more than pressing "approve" at the end of a process. The person in charge must be able to question the output, reject it, correct it and explain the final decision.

This matters because AI systems can sound convincing even when they are wrong. They can produce confident nonsense, repeat hidden bias, miss important context, or give a neat answer to the wrong question. A member of staff who simply accepts whatever the system produces is not exercising oversight. They are only passing the message along. Proper oversight means giving staff both authority and confidence. They must know that they can override an AI recommendation without being treated as obstructive or slow. A healthy business culture should reward careful judgment, especially when technology makes speed feel effortless.

The fourth duty is AI literacy. Organisations using AI are expected to ensure that staff have a basic understanding of the tools they use. This does not mean every employee needs to become a technical expert, nor does it mean turning the office into a classroom. It means people should know what a tool is for, what it must not be used for, what information must never be entered into it, and where its outputs may be unreliable. Training can be simple and practical: onboarding notes, short internal guidance, staff briefings, examples of good and bad use, and records showing that employees received the message. There is no need to turn this into a certification industry, but there must be evidence that the organisation has taken the duty seriously.

The fifth duty concerns general-purpose AI tools used for drafting, coding, research or office support. Much of the legal burden falls on the provider, especially regarding copyright and transparency of training data. Still, businesses cannot simply shrug and say, "That is the vendor's problem." They should retain provider documentation, verify that the supplier provides proper compliance assurances, and ensure that staff do not use prompts to copy-protected works or produce material that infringes someone else's rights. This is part of ordinary supplier due diligence. A company would not buy financial software from a vendor that refused to explain basic security controls. It should take the same attitude toward AI tools.

Beyond these steps, there are sensible protections that every serious business should adopt. A written AI usage policy, employee acknowledgement, monitoring for unauthorised tools, and audit records showing who used which system and for what purpose may seem excessive for low-risk use. In reality, they are practical proof of responsibility.

They also prepare a company for the moment when its use of AI becomes more sensitive. Regulation has a habit of feeling distant until something goes wrong. Then the question is not whether a business meant well, but whether it can show what it did.

The companies that will handle this best are not necessarily the largest or the most technical. They are the ones who treat AI governance as normal management. Before using a tool, they will ask simple but important questions. Do we know what this is? Do we know why we are using it? Could it affect people? Have we told them? Is a human responsible? Have staff been trained? Have we kept the supplier's documents?

These questions are not obstacles to innovation. They are what allow innovation to survive contact with the real world.

The EU AI Act should therefore be seen less as a burden and more as a warning against carelessness. For most businesses, compliance is not about fear. It is about discipline, honesty and respect for the people on the other side of the screen. The time for AI accountability is here, and companies that start with common sense will find the rules far less intimidating than those that wait until a problem lands on their desk.

More in People