{"id":32844,"date":"2026-07-25T08:00:00","date_gmt":"2026-07-25T06:00:00","guid":{"rendered":"https:\/\/pegamento.nl\/niet-gecategoriseerd\/how-do-you-ensure-compliance-with-the-ai-act-when-using-multiple-ai-tools\/"},"modified":"2026-07-25T10:00:50","modified_gmt":"2026-07-25T08:00:50","slug":"how-do-you-ensure-compliance-with-the-ai-act-when-using-multiple-ai-tools","status":"publish","type":"post","link":"https:\/\/pegamento.nl\/en\/contact-center\/how-do-you-ensure-compliance-with-the-ai-act-when-using-multiple-ai-tools\/","title":{"rendered":"How do you ensure compliance with the AI Act when using multiple AI tools?"},"content":{"rendered":"<p>If you use multiple AI tools at the same time, you can ensure compliance with the AI Act by maintaining a central AI inventory, determining the risk level for each tool, and clearly documenting who is internally responsible for which system. The <a href=\"https:\/\/pegamento.nl\/en\/ai-powered-intelligence\/\">EU AI Act<\/a> imposes obligations on both providers and deployers, and it is precisely the combination of multiple tools that makes it difficult to maintain an overview. In this article, we answer the most frequently asked questions about AI compliance in a diverse AI tool landscape.  <\/p>\n<h2>Which AI tools are covered by the AI Act?<\/h2>\n<p>The AI Act applies to any AI system that you develop, use, import, or distribute within the EU, regardless of whether it is your own tool or a service provided by a third-party provider. This includes chatbots, decision-support systems, image recognition software, automation platforms, and large language models. If the output of an AI system is used within the EU, the regulation applies even if the system itself was created outside the EU.  <\/p>\n<p>The law distinguishes between four risk levels. Most AI tools that organizations use on a daily basis fall into the \u201cminimal\u201d or \u201climited\u201d risk categories and are therefore largely unregulated or subject to only light transparency requirements. High-risk AI, such as systems used in human resources management, credit assessment, or access to essential services, is subject to strict regulations. Systems that are completely prohibited include those that use subliminal manipulation, perform social scoring, or employ emotion recognition in the workplace.   <\/p>\n<p>In addition, the law introduces a separate regime for General Purpose AI (GPAI) models, such as large language models. Providers of these models have their own documentation and transparency obligations, regardless of the risk category of the specific application. <\/p>\n<h2>How do you know which requirements apply to each AI tool?<\/h2>\n<p>The obligations that apply depend on two factors: the tool\u2019s risk category and your role in the chain. If you are a deployer\u2014that is, an organization that uses an AI system from an external provider\u2014different obligations apply than if you are the provider who develops and markets the system yourself. <\/p>\n<p>As a deployer, you are required to:<\/p>\n<ul>\n<li>to use the system in accordance with the provider&#8217;s user manual<\/li>\n<li>assign human supervision to qualified and trained employees<\/li>\n<li>to retain logs for at least six months<\/li>\n<li>inform employees before a high-risk system is put into service (Article 26(7))<\/li>\n<li>to conduct a data protection impact assessment (DPIA) where applicable<\/li>\n<\/ul>\n<p>For each tool in your portfolio, it is therefore essential to determine whether it constitutes a high-risk system under Annex III of the Regulation. Systems that profile natural persons are always high-risk, regardless of their intended use. Systems that perform only a preparatory or procedural task without posing a significant risk to fundamental rights may fall outside the high-risk category, provided you document this with supporting evidence.  <\/p>\n<h2>What is the biggest risk when combining multiple AI tools?<\/h2>\n<p>The biggest risk when combining multiple AI tools is losing track of who is responsible for what. When different tools from different providers work together in a single process, a responsibility gap can arise: as the deployer, you may assume that the provider covers certain risks, while the provider assumes that you, as the user, will take additional measures. <\/p>\n<p>A second risk is the cumulative impact. An individual tool may pose a low risk, but when multiple systems collectively influence a decision\u2014for example, in a customer contact process where an AI chatbot, a routing system, and a decision model work together\u2014the combined effect may indeed exhibit high-risk characteristics. The AI Act assesses systems based on their actual use and impact, not just their technical design.  <\/p>\n<p>In addition, anyone who adds their name to a system, makes a substantial change to it, or alters its intended purpose in such a way that the system becomes high-risk, becomes a provider themselves, with all the associated obligations. This is a point that is often overlooked when combining or modifying tools. <\/p>\n<h2>How do you create an AI inventory for compliance purposes?<\/h2>\n<p>An AI inventory is a structured overview of all AI systems used by your organization, including their risk category, provider, intended use, and the person responsible for them within the organization. Compiling such an inventory is the practical foundation of any AI compliance approach. <\/p>\n<p>Follow these steps to create a practical inventory:<\/p>\n<ol>\n<li><strong>Identify all AI tools<\/strong>, including those used indirectly through SaaS platforms or built-in features in existing software.<\/li>\n<li><strong>Determine the risk category for each tool<\/strong> based on its intended use and the Annex III criteria of the AI Act.<\/li>\n<li><strong>Define your organization&#8217;s role<\/strong>: Are you a deployer, a provider, or both?<\/li>\n<li><strong>Document the<\/strong> provider&#8217;s <strong>user manual<\/strong> and the internal agreements regarding human oversight.<\/li>\n<li><strong>Record the logging requirements<\/strong> for each tool and ensure that logs are retained for at least six months for high-risk systems.<\/li>\n<li><strong>Assign each tool to a specific person<\/strong> within your organization.<\/li>\n<\/ol>\n<p>Keep the inventory up to date. AI tools are updated regularly, and an update may change the risk category or the applicable obligations. Therefore, do not treat the inventory as a one-time document, but as a living record.  <\/p>\n<h2>Who is responsible for AI Act compliance within an organization?<\/h2>\n<p>Compliance with the AI Act is not the responsibility of a single person or department. In practice, at least three roles are involved: the operational owner of the tool, the IT or digital transformation manager, and the privacy or compliance officer. For high-risk systems, senior management is also responsible, because the regulation requires that human oversight be entrusted to competent and trained individuals.  <\/p>\n<p>The Privacy Officer plays a key role in conducting data protection impact assessments (DPIAs), which are required when a high-risk AI system processes personal data. The HR department is involved in the obligation to inform employees before high-risk systems are put into use. <\/p>\n<p>A practical consideration: The AI Act stipulates that individuals who are subject to a decision made by a high-risk system may, pursuant to Article 86, request an explanation of the determining factors. Your organization must be able to provide that explanation. This requires not only technical knowledge of the system, but also clear internal processes and a designated point of contact.  <\/p>\n<h2>How do you stay compliant when AI tools are updated regularly?<\/h2>\n<p>Maintaining compliance amid regular updates requires a fixed review process that is triggered as soon as an AI tool undergoes a significant change. An update can alter a system\u2019s intended use, underlying data, or output, which can have direct implications for the risk category and applicable obligations. <\/p>\n<p>Determine internally what a \u201csubstantial modification\u201d means for your tool ecosystem. The AI Act stipulates that anyone who makes a substantial modification to a system becomes a provider themselves. That\u2019s a line you\u2019ll want to monitor carefully, especially if you\u2019re customizing or integrating AI tools into your own processes.  <\/p>\n<p>Practical steps to stay up to date:<\/p>\n<ul>\n<li>Proactively ask providers for changelogs and release notes with every update.<\/li>\n<li>With each significant update, reassess the risk category in your AI inventory.<\/li>\n<li>Check whether the supplier&#8217;s user manual has been updated and update your internal work instructions accordingly.<\/li>\n<li>Ensure that employees who work with high-risk systems are informed of any relevant changes.<\/li>\n<li>Schedule a full review of your AI inventory at least once a year, and more frequently if the tool landscape is changing rapidly.<\/li>\n<\/ul>\n<p>The phased implementation of the AI Act will continue through 2027, with reviews in 2028 and 2029. High-risk Annex III systems will be subject to full compliance requirements as of August 2, 2026. This gives organizations the flexibility to build their compliance process step by step, but makes a structured approach all the more important now.  <\/p>\n<h2>How Pegamento Helps with AI Compliance<\/h2>\n<p>Tracking AI compliance across multiple tools is exactly the kind of challenge where a fragmented vendor landscape can cause problems. We help organizations gain control of their AI environment\u2014from assessment to implementation\u2014all under one roof, without the need for complex coordination among multiple parties. <\/p>\n<p>What we offer in the areas of AI compliance and responsible AI use:<\/p>\n<ul>\n<li><strong>Overview and Assessment<\/strong>: We help you identify which AI systems you use and the obligations associated with them.<\/li>\n<li><strong>Responsible AI Implementation<\/strong>: Our <a href=\"https:\/\/pegamento.nl\/en\/agentic-ai-for-customer-service\/\">Agentic AI solutions for customer service<\/a> are designed with human oversight as a core principle, not as an afterthought. Agentic AI thus represents an evolution from task-oriented bots to self-thinking assistants that take the initiative independently, but always within clear guidelines. <\/li>\n<li><strong>No costly custom development, but a smart combination of proven modules<\/strong>: you get a tailored solution that fits your organization and compliance requirements, without the costs and risks of fully custom-built systems.<\/li>\n<li><strong>A single point of contact<\/strong>: from consultation to implementation and management, so you always know who is responsible.<\/li>\n<li><strong>ISO 27001, ISO 9001, and ISO 26000 certified<\/strong>: information security and quality are embedded in our work processes.<\/li>\n<\/ul>\n<p>Would you like to know where your organization stands right now in terms of AI compliance? <a href=\"https:\/\/pegamento.nl\/en\/contact-2\/\">Contact us<\/a>, and we\u2019d be happy to help you figure it out.<\/p>\n        <div class=\"wp-block-seoaic-faq-block\">\n            <h2 class=\"seoaic-faq-section-title\">Frequently Asked Questions<\/h2>\n                            <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        What are the fines for non-compliance with the AI Act?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        The AI Act establishes a tiered system of fines based on the severity of the violation. Fines for using prohibited AI systems can reach up to 35 million euros or 7% of global annual revenue. Violations of obligations regarding high-risk systems are subject to fines of up to 15 million euros or 3% of revenue, and providing inaccurate information to regulators can result in fines of up to 7.5 million euros or 1% of revenue. Precisely because the fines are substantial, it pays to invest in a solid compliance structure now.                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        Do I need to actively inform my employees that they are working with an AI system?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        Yes, for high-risk AI systems, Article 26(7) of the AI Act requires deployers to inform employees before the system is put into use. This also applies when an existing system is significantly modified. In practice, this means you must establish an internal communication process\u2014preferably linked to your AI inventory\u2014so that every relevant employee is informed in a timely and verifiable manner.                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        How do I handle AI functionality that is already built into software I use, such as a CRM or HR platform?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        Built-in AI features in SaaS platforms are also subject to the AI Act if you actively use them within the EU. Check with your software vendor to find out which AI functionality is active, what its intended use is, and whether the system is classified as high-risk. Include these systems in your AI inventory, even if you did not intentionally purchase them as \u2018AI tools,\u2019 because as a deployer, you are responsible for their use.                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        When is my organization considered a &#039;provider&#039; rather than a &#039;deployer&#039;?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        Your organization becomes a provider as soon as you market an AI system under your own name, substantially modify an existing system, or alter the intended use in such a way that the system falls into a higher risk category. This is a common pitfall when integrating or fine-tuning existing AI models into your own processes. As a provider, you are subject to significantly stricter obligations, including conformity assessments, technical documentation, and registration in the EU database.                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        How do I combine AI Act compliance with existing GDPR and DPIA obligations?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        The AI Act and the GDPR overlap when it comes to data processing: when a high-risk AI system processes personal data, you are required under both regulations to conduct a DPIA. In practice, you can combine these processes by expanding your existing DPIA template to include AI-specific questions about risk category, human oversight, and logging requirements. Involve your Privacy Officer early in the AI inventory process to avoid duplication of effort and achieve an integrated compliance approach.                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        Are there any tools or templates available to help set up an AI inventory more quickly?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        The European Commission and national data protection authorities, including the Dutch Data Protection Authority, publish guidelines and working documents that you can use as a basis. In addition, frameworks such as the NIST AI Risk Management Framework and ISO\/IEC 42001 offer structured methods for AI governance that align well with the AI Act requirements. To get started practically, you can also collaborate with a specialized partner that has already developed a working inventory methodology, so you don\u2019t have to start from scratch.                    <\/p>\n                <\/div>\n                                <div class=\"seoaic-faq-item\">\n                    <h3 class=\"seoaic-question\">\n                        What should I do if an AI provider discontinues a tool or changes its services?                    <\/h3>\n                    <p class=\"seoaic-answer\">\n                        If a provider discontinues or significantly changes its service, this has direct consequences for your compliance status: the user manual you, as the deployer, are permitted to rely on becomes invalid, and you must reassess whether and how you can still use the system responsibly. Always include provisions in contracts with AI providers regarding notification of changes, transfer of documentation, and continuity guarantees. Also, make sure your AI inventory includes a column for contract expiration dates and scheduled review dates, so you don\u2019t run into any surprises.                    <\/p>\n                <\/div>\n                        <\/div>\n        ","protected":false},"excerpt":{"rendered":"<p>Using multiple AI tools while staying compliant? Discover how a centralized AI inventory makes all the difference. <\/p>\n","protected":false},"author":2,"featured_media":32845,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[500],"tags":[],"class_list":["post-32844","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-contact-center"],"_links":{"self":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/32844","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/comments?post=32844"}],"version-history":[{"count":2,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/32844\/revisions"}],"predecessor-version":[{"id":32847,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/32844\/revisions\/32847"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/media\/32845"}],"wp:attachment":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/media?parent=32844"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/categories?post=32844"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/tags?post=32844"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}