Fundamentals

The EU AI Act: your processes are the substrate of compliance

June 16, 2026 · aiio

The EU AI Act doesn’t regulate AI in a vacuum, but AI in use — and use means process. So what it asks for is traceability at the process level: where AI acts, for what purpose, under what human oversight, with what risk at which point. If you don’t have your real as-is at hand, you can’t evidence it.

The EU AI Act is here, and many teams’ first reaction is to look at the technology: which model, which vendor, which risk class? That’s half the question. The other half is procedural: in which workflow does this AI act — and who carries the result onward? A classifier that pre-sorts applications isn’t abstractly “high-risk”. It is high-risk because, at a specific point in a specific process, it affects people.

The AI Act doesn’t regulate models in a vacuum, but AI in use. In use means: process.

What does the EU AI Act fundamentally require for your processes?

Simplified — and without being legal advice — the regulation requires traceability for relevant systems: where AI is used, for what purpose, under what human oversight, with what risk at which point. Those aren’t model properties. They’re process properties.

And this is where the pattern that makes every audit expensive repeats itself: the knowledge exists — in tickets, in tool configs, in the heads of the people who set up the bot. What’s missing is the form in which it becomes inspectable. It’s the same translation problem as with DORA and NIS2 — just a different standard in front of it.

Why static docs lie especially fast here

AI usage shifts faster than classic processes. A team tries a new tool, a prompt gets adjusted, a manual step falls away. Documentation describing the state of six months ago isn’t just incomplete under the AI Act — it describes a use that no longer exists. How quickly that happens is in Why your process diagram lies after three months.

The approach: read AI usage from the living context

Instead of sending a questionnaire around the departments, the real as-is can be pulled from what already exists:

  1. Name the sources — where does AI run today? Automations, tickets, tool exports, the conversations where “we’ll let the tool handle that now” gets said.
  2. Map the points of use — ProcessForge locates which AI acts at which point of which system, and where a human is in the loop.
  3. Pull the artifact — an inspectable overview of AI uses, referenced back to the source, instead of a self-assessment from memory.

This doesn’t automatically make you “compliant” — that decision stays with your responsible people. But it gives them the basis on which to make it at all. Why AI optimizes into the void without the real process context is in AI in processes needs context.

The one sentence

The AI Act is less a technology topic than a visibility topic: those who see their AI uses in the real process can evidence them — those who only suspect them write a questionnaire.

To try it: Bring a concrete AI use that’s on your mind for the AI Act into the demo call — we’ll map it live from a real source.

Request a demo

Show us your trigger.

We’ll build the first artifact from it live in a call — business email & last name are enough.

What’s on your plate right now?
AuditAI & AutomationChange & OnboardingTransformationnot sure yet

Business email & last name are enough. We’ll reply with a named contact. Product updates only if you opt in above.

How we handle your details is explained in our privacy policy.

Thanks — we’ve got your request. A named contact will be in touch shortly.