{"id":32844,"date":"2026-07-25T08:00:00","date_gmt":"2026-07-25T06:00:00","guid":{"rendered":"https:\/\/pegamento.nl\/niet-gecategoriseerd\/how-do-you-ensure-compliance-with-the-ai-act-when-using-multiple-ai-tools\/"},"modified":"2026-07-25T10:00:50","modified_gmt":"2026-07-25T08:00:50","slug":"how-do-you-ensure-compliance-with-the-ai-act-when-using-multiple-ai-tools","status":"publish","type":"post","link":"https:\/\/pegamento.nl\/en\/contact-center\/how-do-you-ensure-compliance-with-the-ai-act-when-using-multiple-ai-tools\/","title":{"rendered":"How do you ensure compliance with the AI Act when using multiple AI tools?"},"content":{"rendered":"<p>If you use multiple AI tools at the same time, you can ensure compliance with the AI Act by maintaining a central AI inventory, determining the risk level for each tool, and clearly documenting who is internally responsible for which system. The <a href=\"https:\/\/pegamento.nl\/en\/ai-powered-intelligence\/\">EU AI Act<\/a> imposes obligations on both providers and deployers, and it is precisely the combination of multiple tools that makes it difficult to maintain an overview. In this article, we answer the most frequently asked questions about AI compliance in a diverse AI tool landscape.  <\/p>\n<h2>Which AI tools are covered by the AI Act?<\/h2>\n<p>The AI Act applies to any AI system that you develop, use, import, or distribute within the EU, regardless of whether it is your own tool or a service provided by a third-party provider. This includes chatbots, decision-support systems, image recognition software, automation platforms, and large language models. If the output of an AI system is used within the EU, the regulation applies even if the system itself was created outside the EU.  <\/p>\n<p>The law distinguishes between four risk levels. Most AI tools that organizations use on a daily basis fall into the \u201cminimal\u201d or \u201climited\u201d risk categories and are therefore largely unregulated or subject to only light transparency requirements. High-risk AI, such as systems used in human resources management, credit assessment, or access to essential services, is subject to strict regulations. Systems that are completely prohibited include those that use subliminal manipulation, perform social scoring, or employ emotion recognition in the workplace.   <\/p>\n<p>In addition, the law introduces a separate regime for General Purpose AI (GPAI) models, such as large language models. Providers of these models have their own documentation and transparency obligations, regardless of the risk category of the specific application. <\/p>\n<h2>How do you know which requirements apply to each AI tool?<\/h2>\n<p>The obligations that apply depend on two factors: the tool\u2019s risk category and your role in the chain. If you are a deployer\u2014that is, an organization that uses an AI system from an external provider\u2014different obligations apply than if you are the provider who develops and markets the system yourself. <\/p>\n<p>As a deployer, you are required to:<\/p>\n<ul>\n<li>to use the system in accordance with the provider&#8217;s user manual<\/li>\n<li>assign human supervision to qualified and trained employees<\/li>\n<li>to retain logs for at least six months<\/li>\n<li>inform employees before a high-risk system is put into service (Article 26(7))<\/li>\n<li>to conduct a data protection impact assessment (DPIA) where applicable<\/li>\n<\/ul>\n<p>For each tool in your portfolio, it is therefore essential to determine whether it constitutes a high-risk system under Annex III of the Regulation. Systems that profile natural persons are always high-risk, regardless of their intended use. Systems that perform only a preparatory or procedural task without posing a significant risk to fundamental rights may fall outside the high-risk category, provided you document this with supporting evidence.  <\/p>\n<h2>What is the biggest risk when combining multiple AI tools?<\/h2>\n<p>The biggest risk when combining multiple AI tools is losing track of who is responsible for what. When different tools from different providers work together in a single process, a responsibility gap can arise: as the deployer, you may assume that the provider covers certain risks, while the provider assumes that you, as the user, will take additional measures. <\/p>\n<p>A second risk is the cumulative impact. An individual tool may pose a low risk, but when multiple systems collectively influence a decision\u2014for example, in a customer contact process where an AI chatbot, a routing system, and a decision model work together\u2014the combined effect may indeed exhibit high-risk characteristics. The AI Act assesses systems based on their actual use and impact, not just their technical design.  <\/p>\n<p>In addition, anyone who adds their name to a system, makes a substantial change to it, or alters its intended purpose in such a way that the system becomes high-risk, becomes a provider themselves, with all the associated obligations. This is a point that is often overlooked when combining or modifying tools. <\/p>\n<h2>How do you create an AI inventory for compliance purposes?<\/h2>\n<p>An AI inventory is a structured overview of all AI systems used by your organization, including their risk category, provider, intended use, and the person responsible for them within the organization. Compiling such an inventory is the practical foundation of any AI compliance approach. <\/p>\n<p>Follow these steps to create a practical inventory:<\/p>\n<ol>\n<li><strong>Identify all AI tools<\/strong>, including those used indirectly through SaaS platforms or built-in features in existing software.<\/li>\n<li><strong>Determine the risk category for each tool<\/strong> based on its intended use and the Annex III criteria of the AI Act.<\/li>\n<li><strong>Define your organization&#8217;s role<\/strong>: Are you a deployer, a provider, or both?<\/li>\n<li><strong>Document the<\/strong> provider&#8217;s <strong>user manual<\/strong> and the internal agreements regarding human oversight.<\/li>\n<li><strong>Record the logging requirements<\/strong> for each tool and ensure that logs are retained for at least six months for high-risk systems.<\/li>\n<li><strong>Assign each tool to a specific person<\/strong> within your organization.<\/li>\n<\/ol>\n<p>Keep the inventory up to date. AI tools are updated regularly, and an update may change the risk category or the applicable obligations. Therefore, do not treat the inventory as a one-time document, but as a living record.  <\/p>\n<h2>Who is responsible for AI Act compliance within an organization?<\/h2>\n<p>Compliance with the AI Act is not the responsibility of a single person or department. In practice, at least three roles are involved: the operational owner of the tool, the IT or digital transformation manager, and the privacy or compliance officer. For high-risk systems, senior management is also responsible, because the regulation requires that human oversight be entrusted to competent and trained individuals.  <\/p>\n<p>The Privacy Officer plays a key role in conducting data protection impact assessments (DPIAs), which are required when a high-risk AI system processes personal data. The HR department is involved in the obligation to inform employees before high-risk systems are put into use. <\/p>\n<p>A practical consideration: The AI Act stipulates that individuals who are subject to a decision made by a high-risk system may, pursuant to Article 86, request an explanation of the determining factors. Your organization must be able to provide that explanation. This requires not only technical knowledge of the system, but also clear internal processes and a designated point of contact.  <\/p>\n<h2>How do you stay compliant when AI tools are updated regularly?<\/h2>\n<p>Maintaining compliance amid regular updates requires a fixed review process that is triggered as soon as an AI tool undergoes a significant change. An update can alter a system\u2019s intended use, underlying data, or output, which can have direct implications for the risk category and applicable obligations. <\/p>\n<p>Determine internally what a \u201csubstantial modification\u201d means for your tool ecosystem. The AI Act stipulates that anyone who makes a substantial modification to a system becomes a provider themselves. That\u2019s a line you\u2019ll want to monitor carefully, especially if you\u2019re customizing or integrating AI tools into your own processes.  <\/p>\n<p>Practical steps to stay up to date:<\/p>\n<ul>\n<li>Proactively ask providers for changelogs and release notes with every update.<\/li>\n<li>With each significant update, reassess the risk category in your AI inventory.<\/li>\n<li>Check whether the supplier&#8217;s user manual has been updated and update your internal work instructions accordingly.<\/li>\n<li>Ensure that employees who work with high-risk systems are informed of any relevant changes.<\/li>\n<li>Schedule a full review of your AI inventory at least once a year, and more frequently if the tool landscape is changing rapidly.<\/li>\n<\/ul>\n<p>The phased implementation of the AI Act will continue through 2027, with reviews in 2028 and 2029. High-risk Annex III systems will be subject to full compliance requirements as of August 2, 2026. This gives organizations the flexibility to build their compliance process step by step, but makes a structured approach all the more important now.  <\/p>\n<h2>How Pegamento Helps with AI Compliance<\/h2>\n<p>Tracking AI compliance across multiple tools is exactly the kind of challenge where a fragmented vendor landscape can cause problems. We help organizations gain control of their AI environment\u2014from assessment to implementation\u2014all under one roof, without the need for complex coordination among multiple parties. <\/p>\n<p>What we offer in the areas of AI compliance and responsible AI use:<\/p>\n<ul>\n<li><strong>Overview and Assessment<\/strong>: We help you identify which AI systems you use and the obligations associated with them.<\/li>\n<li><strong>Responsible AI Implementation<\/strong>: Our <a href=\"https:\/\/pegamento.nl\/en\/agentic-ai-for-customer-service\/\">Agentic AI solutions for customer service<\/a> are designed with human oversight as a core principle, not as an afterthought. Agentic AI thus represents an evolution from task-oriented bots to self-thinking assistants that take the initiative independently, but always within clear guidelines. <\/li>\n<li><strong>No costly custom development, but a smart combination of proven modules<\/strong>: you get a tailored solution that fits your organization and compliance requirements, without the costs and risks of fully custom-built systems.<\/li>\n<li><strong>A single point of contact<\/strong>: from consultation to implementation and management, so you always know who is responsible.<\/li>\n<li><strong>ISO 27001, ISO 9001, and ISO 26000 certified<\/strong>: information security and quality are embedded in our work processes.<\/li>\n<\/ul>\n<p>Would you like to know where your organization stands right now in terms of AI compliance? <a href=\"https:\/\/pegamento.nl\/en\/contact-2\/\">Contact us<\/a>, and we\u2019d be happy to help you figure it out.<\/p>\n<div class=\"wp-block-seoaic-faq-block\">\n    <h2 class=\"seoaic-faq-section-title\">Frequently Asked Questions<\/h2>\n            <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Wat zijn de boetes als je niet voldoet aan de AI Act?            <\/h3>\n            <p class=\"seoaic-answer\">\n                De AI Act kent een gelaagd boetestelsel afhankelijk van de ernst van de overtreding. Voor het gebruik van verboden AI-systemen kunnen boetes oplopen tot 35 miljoen euro of 7% van de wereldwijde jaaromzet. Bij schending van verplichtingen voor hoog-risico systemen gelden boetes tot 15 miljoen euro of 3% van de omzet, en voor het verstrekken van onjuiste informatie aan toezichthouders tot 7,5 miljoen euro of 1% van de omzet. Juist omdat de boetes aanzienlijk zijn, loont het om nu al te investeren in een solide compliancestructuur.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Moet ik mijn medewerkers actief informeren dat ze met een AI-systeem werken?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Ja, voor hoog-risico AI-systemen verplicht Artikel 26(7) van de AI Act deployers om medewerkers te informeren v\u00f3\u00f3rdat het systeem in gebruik wordt genomen. Dit geldt ook wanneer een bestaand systeem significant wordt gewijzigd. Praktisch betekent dit dat je een intern communicatieproces moet inrichten, bij voorkeur gekoppeld aan je AI-inventaris, zodat iedere relevante medewerker tijdig en aantoonbaar is ge\u00efnformeerd.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Hoe ga ik om met AI-functionaliteit die al is ingebouwd in software die ik gebruik, zoals een CRM of HR-platform?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Ingebouwde AI-functies in SaaS-platformen vallen ook onder de AI Act als je ze actief inzet binnen de EU. Vraag bij je softwareleverancier na welke AI-functionaliteit actief is, wat het beoogde gebruiksdoel is en of het systeem als hoog-risico wordt geclassificeerd. Neem deze systemen op in je AI-inventaris, ook als je ze niet bewust hebt aangeschaft als &#8216;AI-tool&#8217;, want als deployer ben jij verantwoordelijk voor het gebruik.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Wanneer wordt mijn organisatie beschouwd als &#039;aanbieder&#039; in plaats van &#039;deployer&#039;?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Je organisatie wordt aanbieder zodra je een AI-systeem onder eigen naam op de markt brengt, een bestaand systeem substantieel wijzigt, of het beoogde gebruiksdoel zodanig aanpast dat het systeem in een hogere risicocategorie terechtkomt. Dit is een veelgemaakte valkuil bij het integreren of fine-tunen van bestaande AI-modellen in eigen processen. Als aanbieder gelden aanzienlijk zwaardere verplichtingen, waaronder conformiteitsbeoordelingen, technische documentatie en registratie in de EU-databank.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Hoe combineer ik AI Act compliance met bestaande AVG- en DPIA-verplichtingen?            <\/h3>\n            <p class=\"seoaic-answer\">\n                De AI Act en de AVG overlappen elkaar op het punt van gegevensverwerking: wanneer een hoog-risico AI-systeem persoonsgegevens verwerkt, ben je op grond van beide regelgevingen verplicht een DPIA uit te voeren. In de praktijk kun je deze processen combineren door je bestaande DPIA-template uit te breiden met AI-specifieke vragen over risicocategorie, menselijk toezicht en loggingverplichtingen. Betrek je Privacy Officer vroegtijdig bij de AI-inventarisatie om dubbel werk te voorkomen en een ge\u00efntegreerde complianceaanpak te realiseren.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Zijn er tools of sjablonen beschikbaar om sneller een AI-inventaris op te zetten?            <\/h3>\n            <p class=\"seoaic-answer\">\n                De Europese Commissie en nationale toezichthouders, waaronder de Autoriteit Persoonsgegevens, publiceren richtlijnen en werkdocumenten die je als basis kunt gebruiken. Daarnaast bieden frameworks zoals de NIST AI Risk Management Framework en ISO\/IEC 42001 gestructureerde methoden voor AI-governance die goed aansluiten op de AI Act-vereisten. Voor een praktische start kun je ook samenwerken met een gespecialiseerde partner die al een werkende inventarisatiemethodiek heeft ontwikkeld, zodat je niet vanaf nul hoeft te beginnen.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Wat moet ik doen als een AI-aanbieder stopt met een tool of zijn dienstverlening wijzigt?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Als een aanbieder zijn dienst stopzet of significant wijzigt, heeft dit directe gevolgen voor jouw compliancestatus: de gebruiksaanwijzing waarop jij als deployer mag vertrouwen vervalt, en je moet opnieuw beoordelen of en hoe je het systeem nog verantwoord kunt inzetten. Neem in contracten met AI-aanbieders altijd bepalingen op over kennisgeving bij wijzigingen, overdracht van documentatie en continu\u00efteitsgaranties. Zorg daarnaast dat je AI-inventaris een kolom bevat voor contractvervaldata en geplande evaluatiemomenten, zodat je niet voor verrassingen komt te staan.            <\/p>\n        <\/div>\n        <\/div>\n","protected":false},"excerpt":{"rendered":"<p>Using multiple AI tools while staying compliant? Discover how a centralized AI inventory makes all the difference. <\/p>\n","protected":false},"author":2,"featured_media":32845,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[500],"tags":[],"class_list":["post-32844","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-contact-center"],"_links":{"self":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/32844","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/comments?post=32844"}],"version-history":[{"count":2,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/32844\/revisions"}],"predecessor-version":[{"id":32847,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/32844\/revisions\/32847"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/media\/32845"}],"wp:attachment":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/media?parent=32844"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/categories?post=32844"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/tags?post=32844"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}