

AI Unlocked: Relevant AI laws
for professional application
There are many relevant rules and non-legal considerations when developing and using AI. The presentation provided a general overview of these rules and considerations, focusing on the most important aspects of the AI Act. A four-step action plan was proposed at the end. This blog post summarizes the key points of the presentation given on 15 October 2025, based on this action plan.
Step 1: Map
The first step is being able to recognize an AI system as defined by the AI Act. AI is an umbrella term covering many applications, including popular Large Language Models such as ChatGPT. While the AI Act contains a broad definition of AI systems, many will not be subject to its specific obligations as they do not pose a substantial risk to fundamental rights.
Step 2: Evaluate
The second step is to categorize the identified AI systems into one of four risk categories:
- AI systems that pose an unacceptable risk have been prohibited since February 2025. This includes emotion recognition systems used at work or in education.
- AI systems that pose a high risk will be subject to several mandatory measures. For example, this relates to many AI systems used in an HR context. However, the AI Act provides an exception to this rule for AI systems that do not pose a significant risk. This applies, for example, when they are used to improve the results of previously completed human activities.
- AI systems that pose a limited risk will need to comply with specific transparency obligations. This relates to the use of chatbots, for example.
- AI systems that pose minimal or no risk are exempt from any additional obligations under the AI Act. However, there will still be a need to comply with the AI literacy obligation.
Step 3: Plan
In the third step, a concrete plan must be developed for implementing the above AI systems. This should include information on who needs to be informed, the measures that need to be implemented, how the AI systems will be monitored, when they must be evaluated, the measures required for AI literacy, and whether there are any registration requirements.
Setting up a flexible plan will make it possible to prioritize. The risk categories and deadlines in the AI Act can be a useful guide for setting priorities. A well-thought-out and well-documented plan also demonstrates to the authorities that steps are being taken towards compliance, even if a company has not yet achieved it.
Step 4: AI literacy
The AI-literacy part of the plan must be carried out in the fourth step. It is important to remember that AI literacy is an ongoing process, not a goal. In other words, implementing an AI usage policy and providing one-off AI training will not make you AI-literate. Similarly, providing employees with access to AI tools will not necessarily make them more productive. A fool with a tool is still a fool. Therefore, tailored training for an AI tool at regular intervals is often recommended.
That said, an AI policy is highly recommended for most companies. At a minimum, this policy should contain rules on prohibited use and provide for sanctions when an employee infringes this policy.
Human
The presentation concluded by emphasizing the importance of human involvement in all stages of AI tool development, use and discontinuation.

By Matthias Vandamme: PhD Candidate / Academic Assistant / Attorney
Matthias, a lawyer since September 2020, specializes in technology and data law. He has authored several works on data protection and AI and is a frequent speaker on these subjects. He earned his Master’s in Law with distinction from the Free University of Brussels (VUB) in July 2020, completed internships in data and tech law, and became a certified Data Protection Officer in 2023.


