One question decides where you stand:
Can you see every AI system running inside your company, and prove it is under control?
For most organisations the answer today is "not fully." In practice, organisations need to do three things:
- Know what AI you run, and sort it by risk.
- Put clear ownership and controls on the systems that matter.
- Prove they are safe, rather than simply saying so.
Within your company, people are already using AI for personal productivity. A handful of super users configure assistants and workflows for their teams. And companies like Faktion build custom engineered AI systems on top of your own data and processes.
Let's talk about :
- What the Act asks of you.
- The five questions on how much attention each AI use case needs.
- The three levels of AI: plug-and-play, configurable and engineered AI systems.
- What human oversight looks like in practice.
This article explains how to turn that gap into a standard operating capability.
What the EU AI Act asks of you
Behind the legal text, the EU AI Act comes down to three things: a risk framework, the use cases it applies to, and the governance it expects:
1. The risk framework
The Act follows a risk-based structure: prohibited practices, high-risk systems, specific transparency obligations, and most other uses facing no specific AI Act duties.
- Prohibited practices are banned outright: social scoring, manipulation, and certain biometric or emotion-recognition uses.
- High-risk AI is allowed but controlled: hiring, credit, education, essential services and similar sensitive domains.
- Transparency-related AI is allowed, but people must be told when they are dealing with AI or AI-generated content.
- Minimal or no-risk AI covers most business use: no specific legal duties, but still real commercial, privacy and quality risk.
As a result, regulatory risk does not track technical complexity. A simple configured tool can be high-risk in hiring, while a complex system can stay low-risk optimising an internal process.
2. The use cases it reaches
- The Act reaches far beyond Legal: procurement, product, HR, marketing, customer operations and security are all in scope.
- The same model can carry different obligations depending on the specific use case. Summarising a meeting and ranking job applicants are not the same in the eyes of the Act.
3. The governance it expects
- Visibility: an inventory of the systems, tools, models and AI-enabled vendor products in use.
- Ownership: a named business owner and technical owner for every material use case, controlled across its full lifecycle.
- Evidence: policies are not enough. You must be able to show how a system was designed, tested, monitored and supervised.
Some of these obligations already applied before August. High-risk controls take months to build, which makes now the moment to start.
This needs to be on your radar: 5 questions to ask
The Act becomes concrete the moment you apply it to your own systems. For each place AI is used in your organisation, five questions decide how much attention it needs.
- Where is it? Can you even see it, including the AI hidden inside software you already pay for?
- What is it? What type of AI is this, and how risky is the use case? One decides how much control it needs; the other decides which legal obligations might apply.
- What can it do? Is it helping one person, supporting a team, embedded in a process, influencing decisions about people, or able to act on its own?
- How far can it go without a human? An AI that drafts a supplier email is a very different risk from one that sends it, changes the order and triggers payment. Same model, very different exposure.
- Could you prove it? If something went wrong tomorrow, could you reconstruct what the system did and show it was under control?
Start with the processes that carry the most business or human impact, the handful that would do the most damage if they went wrong. Get those under control first, then work down the list.
Faktion's three levels of AI
At Faktion we group enterprise AI into three levels: plug-and-play, configurable and engineered.
They are an operating model for deciding how a system is designed, who owns it and what oversight it needs, based on the use case and the degree of control.
Each level offers a different degree of control, auditability and human oversight, the same qualities the EU AI Act relies on.
- Level 1, Plug-and-play AI: standard vendor tools used as they come, such as enterprise ChatGPT, Claude, Gemini or Microsoft 365 Copilot. Fast to adopt, but you control little beyond how people use them, and traceability is limited.
- Level 2, Configurable AI: platforms adapted to a task or team without building from scratch, such as Copilot Studio, Claude Cowork or a tailored assistant. You control data sources, instructions and permissions, so more can be logged and reviewed.
- Level 3, Engineered AI: custom systems where AI is built onto your data, tools and processes. You own the design, and with it full logging, evaluation, oversight and evidence.
Which level for which risk
The higher the risk of a use case, the more auditability and human oversight the AI Act demands, and the higher the level it needs.
This is the call Faktion makes with you. We know these tools, their strengths and their limits, in depth. Give us a use case and its risk, and we can say which level it needs, which specific tool fits, and the exact conditions, logging, human review, disclosure, that make it compliant.
Sometimes the answer is “yes, in a configured assistant, with these guardrails.” Sometimes it is “no, this has to be engineered.”.
Human oversight, with the evidence to prove it
High-risk and many transparency use cases require a human to approve AI output before it reaches a customer.
Higher legal risk does not automatically require a higher Faktion implementation level. It usually requires greater control and assurance, which may push toward configurable or engineered AI depending on the platform’s capabilities.
A reviewer who cannot see the source evidence, applied rules, warnings and audit history behind that output is approving a black box.
Take an insurer drafting claim-decision letters. If the reviewer sees only the finished text, there is no way to judge whether the policy was read correctly. Faktion builds the interface that puts the source documents, the flagged passages and the reasoning in front of the reviewer, so the check is fast, structured and accurate.
That is the second thing we do: turn a chosen solution into a production system with the oversight, interfaces and evidence the EU AI Act expects.
Turn AI governance into capability
Most organisations have plenty of AI tools running. Far fewer can prove those are safe, effective and under control. This is the call we make at Faktion: which level a use case needs, which tool fits, and what has to be in place around it.
Our AI Advisory maps your use cases to the right level and the right controls. Our AI Engineering builds and operationalises the systems behind them, with the oversight and evidence the Act requires. From one assistant to a full agentic platform, Faktion builds AI that stays accountable at every stage.


















