A marketer asks a neural network to write an ad copy. A sales manager generates a commercial proposal. HR uses a service to quickly screen resumes. A lawyer receives a contract from a client that has already been “pre-reviewed by artificial intelligence.” An accountant asks an AI assistant to explain a complex letter from a business partner. A department head uploads an internal document to the AI and asks it to “briefly highlight the risks.”
Convenient? Absolutely. Fast? Yes. Responsible? That’s debatable.
The problem isn’t the use of AI itself, but rather this: businesses often use it haphazardly. Without internal rules, without oversight, without understanding exactly what data enters the system, who verifies the results, and who will be held accountable if the algorithm makes a mistake.
Let’s imagine a very real-life scenario. A company manager is preparing a response to an important client. To save time, he enters excerpts from the contract, the correspondence history, amounts, and delivery dates into an AI service and asks, “Write a polite response so that we don’t admit fault.” Within a few minutes, the response is ready. But in doing so, the company may have disclosed confidential information, its commercial position, and part of its future evidence base in a dispute to an external service.
Here’s another example. The HR department uses a service that quickly sorts through resumes. It’s very convenient: instead of a hundred candidates, the system narrows it down to ten. But if no one understands the logic behind why the algorithm “weeded out” the others, the business may unwittingly expose itself to the risk of discrimination. The system could have downgraded candidates based on age, gender, gaps in employment, place of residence, or other characteristics that the employer never even intended to consider.
It is precisely in this context that we should discuss the EU AI Act—the new European regulation on artificial intelligence. Not as just another layer of complex “European bureaucracy,” but as an important signal to businesses: the era of unregulated AI use is gradually coming to an end.
What Is the EU AI Act in Simple Terms
The EU AI Act is a European Union regulation that establishes rules for the development, sale, deployment, and use of artificial intelligence systems.
To put it simply, without getting into legal complexities, Europe is trying to answer a practical question: how to allow businesses, governments, and tech companies to use AI while preventing algorithms from unchecked influence over people.
The purpose of this document is not to ban AI or stifle technology. On the contrary, the EU explicitly recognizes the benefits of artificial intelligence for the economy, medicine, education, transportation, energy, public services, and many other sectors. At the same time, however, the EU also acknowledges the obvious risk: if AI can affect a person’s rights, finances, employment, safety, or reputation, it cannot operate as a “black box” for which no one is accountable.
The preamble to the Regulation states that its goal is to establish a single legal framework for artificial intelligence systems in the EU, to promote the development of human-centric and trustworthy AI, and at the same time ensure a high level of protection for health, safety, and fundamental rights.
For businesses, this means that AI can and should be used. But the more significantly it affects people, the less room there should be for chaos and improvisation.
For example, if a store owner asks AI to come up with a name for a new promotion, that’s one level of risk. If that same business implements an algorithm that automatically determines which customers to offer more expensive terms to, which to deny installment plans, and which to classify as “problem customers”—that’s a whole different story.
In the first case, AI helps with creativity. In the second, it begins to affect people’s real interests.
The main principle: the greater the risk, the more rules
The EU AI Act is not based on the principle of “allow everything” or “ban everything.” Its logic is this: the greater the risk posed by the use of AI, the more rules there are for those who create, sell, or use it.
It’s one thing when AI helps write an ad, translate a letter, or draft a presentation. The risk here is usually low, although even in such cases, it’s worth considering privacy and the quality of the result.
It’s another matter entirely when AI helps screen job candidates. Here, an algorithmic error can affect a person’s career.
An even more serious situation arises when AI assesses a client’s creditworthiness, analyzes consumer behavior, or assists in decision-making in medicine, education, insurance, public services, or the justice system. In these areas, the consequences of an error can be very significant.
In this regard, the Regulation incorporates a so-called risk-based approach. The rules must correspond to the intensity and scale of the risks that AI systems may pose. Certain practices are explicitly prohibited; special requirements are established for high-risk systems; and transparency obligations apply to specific systems.
For a businessperson, this can be explained very simply. AI is like a car. You can drive it. But the faster you go, the more complex the road, and the more people around, the more important the rules, brakes, technical condition, and a responsible driver become.
The simple formula is this: the closer AI gets to a person’s rights, money, work, safety, or reputation—the less “automation without accountability” there should be.
The EU is particularly wary of situations where AI could become a tool for covert influence, control, or discrimination.
This refers, for example, to cases where an algorithm subtly nudges a person toward a certain decision. Or exploits their vulnerabilities—age, health status, financial hardship, or dependence on a service. Or evaluates people based on opaque criteria. Or creates something akin to a “social rating,” where a person is effectively classified and punished for certain behavior, status, or characteristics.
In business, this may not seem like a dystopia, but rather a rather mundane reality.
For example, a financial company uses an algorithm to evaluate customers. Formally, it simply “assists with scoring.” But if the system takes indirect indicators into account—neighborhood, phone model, behavior within the app, time taken to complete the application, social media activity—a person may receive worse terms not because of their actual creditworthiness, but because of an opaque combination of digital traces.
Or a delivery service evaluates couriers using an algorithm. One employee receives fewer orders, another gets worse routes, and a third has a lower internal rating. If a person doesn’t understand why this happened and has no way to appeal it, the technology becomes a hidden boss.
Another example is a customer chatbot. It communicates with customers as if it were a real employee. It makes promises, explains terms and conditions, and advises on how to place an order or file a return. For businesses, this saves time. But if a customer receives the wrong answer, who will be held accountable? The chatbot? The developer? The manager? The company on whose behalf it was communicating?
Biometrics is a particularly sensitive topic: facial features, voice, behavioral traits, and emotions. Technologically, this may seem impressive. But legally and ethically, it’s a very dangerous area, because it’s no longer just about convenience, but about identification, surveillance, and control.
The preamble to the EU AI Act states that AI can be used as a powerful new tool for manipulative and exploitative practices and social control, and that such practices are particularly harmful and contrary to human dignity, freedom, equality, democracy, the rule of law, and fundamental rights.
For businesses, the main takeaway here is simple: the problem doesn’t begin when a company uses the technology. The problem begins when the technology affects a person in a way that they don’t understand, can’t verify, can’t explain, or can’t challenge.
And this is no longer just a matter for “IT people.” It is a matter of management, reputation, compliance, and legal liability.
Why This Is Important for Ukrainian Businesses
A Ukrainian entrepreneur’s initial reaction might be quite understandable: “This is the European Union. What does this have to do with us?” However, the connection is much more practical than it seems.
The EU AI Act could be relevant to a Ukrainian company if it works with EU clients, develops IT or AI products for the European market, provides services to European partners, integrates AI solutions into products used in the EU, or processes the personal data of individuals from the European Union.
Let’s imagine a Ukrainian IT company developing an automated candidate selection module for a German client. The developer’s office is in Ukraine. But the product is used in the EU and affects candidates in Europe. Therefore, the issue of compliance with European regulations is no longer just theoretical.
Or consider a Ukrainian online service that sells services to clients in Poland, Germany, or France and uses an AI chatbot for consultations. If the bot collects data, provides recommendations, or influences the client’s decisions, the business should consider not only convenience but also transparency, data, and accountability.
Another practical scenario: a manufacturing company from Ukraine wants to work with a major European partner. During the due diligence process, the partner may ask not only for financial statements and quality certificates but also about how the company uses AI: whether there is an internal policy, what data is entered, who has access, and whether confidential materials are transferred to third-party services.
Even if a company isn’t directly subject to this Regulation, it still shouldn’t be ignored. It sets a new standard for caution.
At one time, many viewed the GDPR as a distant European issue concerning personal data. Then businesses gradually realized that personal data is not just a spreadsheet of customer phone numbers, but a legal asset and a legal risk. The same logic will apply to artificial intelligence.
The AI Act demonstrates how the broader market is beginning to view AI: not as a toy, not as magic, and not as a “free assistant,” but as a tool capable of producing real-world consequences.
For Ukrainian businesses, this is a signal that it’s better to get things in order now than to later hastily explain to clients, partners, auditors, investors, or the court exactly how the company used AI and why no one was monitoring it.
Where the Real Risks Lie for Businesses
Most often, the risk arises not because a company purchased a complex AI system. An employee uploaded a contract containing confidential terms to a public AI service. A manager entered a client’s personal data into a chatbot. HR used an automated tool to screen candidates, but no one checked whether it discriminated against certain groups of people. The marketing team generated an advertisement that misled consumers. A chatbot on the website gave a customer an incorrect answer, and the customer took it as the company’s official position. A lawyer received a “verified AI” contract from the business that omitted a key risk.
One of the most common examples is a contract.
An entrepreneur uploads a draft contract to an AI service and asks, “Check if everything is okay.” The AI gives a confident response: “The contract is generally balanced.” The person is reassured. But the algorithm may not have understood the real context: which party has the upper hand, what negotiations have already taken place, what the relevant case law is, what the performance risks are, which penalties are truly dangerous, which terms need to be rewritten, and which can be left as is.
The danger here isn’t that the AI is “bad.” The danger is that it can sound confident even when it’s wrong.
Another example is an internal conflict.
A director writes to an AI service: “Prepare a plan to terminate a problematic employee so that they cannot be reinstated through the courts.” And adds details: the employee’s position, behavior, correspondence, and weaknesses. Formally, the director is simply seeking advice. In reality, he could be leaking sensitive information and creating a document that could later be used as evidence of a premeditated termination.
Or consider a situation involving a corporate dispute.
One of the business partners uploads the articles of incorporation, meeting minutes, and correspondence with the other partner to the AI and asks, “How can I remove him from the company’s management?” During a conflict, such digital traces can be just as significant as official documents.
There’s a separate risk—a management risk. A director may not even be aware that employees are already actively using AI in internal processes. Formally, there is no policy, no ban, no permission, and no oversight. But data is already being entered, decisions are already being made, documents are already being created, and customers are already receiving responses.
In such a situation, the company is under the illusion that it “has not yet implemented AI.” In reality, AI has already been implemented—just spontaneously.
And the unplanned implementation of technology in business almost always means one thing: the risks are already there, but no one is accountable yet.
What Businesses Should Do Right Now
Businesses don’t need to panic. And they certainly don’t need to ban AI entirely. That would be unwise. AI is already delivering speed, time savings, and new opportunities for analysis, communication, and automation.
But companies should take a few simple steps.
First, understand exactly where AI is already being used within the company. Not in theory, but in practice: in marketing, sales, HR, contracts, customer service, analytics, accounting, and internal documents.
In practice, this can be very simple: a manager gathers brief information from departments and asks not “Have we officially implemented AI?” but “Which AI services do you actually use in your work?” The answers may surprise you.
Second, you need to determine what data cannot be entered into AI services without special permission. At a minimum, this list should include personal data, trade secrets, financial documents, internal conflicts, negotiation strategies, dispute materials, confidential contracts, and customer information.
Third, establish a rule: important decisions should not be made solely based on an AI’s response. An algorithm can assist, but the responsibility for the final decision must remain with a human.
This is particularly important in HR, finance, client relations, contracts, and disputes. AI can be a good assistant, but it should not be a “silent director” who effectively decides whom to hire, whom to reject, which contract to sign, or what position to take in a dispute.
Fourth, special attention must be paid to the use of AI in the most sensitive areas: HR, customer service, marketing, finance, contracts, personal data, and compliance.
Fifth, employees need to be trained in basic AI literacy. The goal isn’t to turn them into programmers, but to explain practical matters: what can and cannot be fed into AI, when results need to be verified, which decisions should not be left to the algorithm, and who is responsible for the final outcome.
Incidentally, the very concept of AI literacy is explicitly addressed in the EU AI Act. The regulation is based on the premise that participants in the AI ecosystem must have sufficient understanding to make informed decisions regarding AI systems—specifically regarding proper use, interpretation of results, and understanding the impact of decisions made with the help of AI.
And this is a very sensible approach. Most problems with AI arise not from a “machine uprising,” but from human carelessness: copying the wrong data, trusting the wrong answer, failing to verify the result, or failing to establish rules.
In Conclusion
Artificial intelligence is no longer a novelty or a thing of the future. It is a working tool for business. But the operation of any significant tool requires rules.
The EU AI Act is important not only because it is a major European regulation. It is important because it clearly illustrates a new reality: businesses will not be able to use AI for long based on a “we’ll figure it out as we go” approach.
Companies don’t need to fear artificial intelligence. But they need to stop treating it like a toy with no consequences. If AI works with data, documents, customers, employees, or decisions, it’s already part of the risk management system.
The real problem isn’t that an employee opened ChatGPT. The problem is that the company doesn’t know what the employee entered into it, how the response was used, or who verified the result.
The future doesn’t belong to those who ban AI. Nor does it belong to those who mindlessly hand over decisions to it. The future belongs to businesses that use AI quickly, intelligently, and responsibly.
Author: Kirill Iordanov, Attorney at Law, Barristers, LLC
Source: https://dengi.ua/ua/blog/9760717-kiril-iordanov-yak-regulyuvati-shtuchnij-intelekt-u-korporativnomu-sektori