Logo
Logo
AI Act

AI Act: The pressure to participate, the fear of losing control | Clariox Advisory

The AI Act is the newest, and for many companies the most significant, compliance requirement to arrive in recent years, which is also why it is the last and most current article in this series. The pressure to get on the AI train is real: management expects results, competitors are already experimenting, and nobody wants to be the one falling behind. But the pressure runs both ways. Just as strong as the urge to get started is the fear of losing control, of an AI system making a mistake nobody caught in time, or of standing without an answer the day a regulator or a customer asks how you actually govern your AI.

That is the friction the AI Act puts a legal frame around. The law makes it a duty to be able to document that you are in control of your AI systems, no longer just a question of reputation if something goes wrong. And unlike NIS2, DORA and PCI DSS, the AI Act is not limited to one industry. It reaches any organisation, public or private, that develops or uses AI, whether in HR, manufacturing, healthcare, education, finance or customer service.

This article is the third and final part of a series on the shared foundation behind NIS2, DORA/PCI DSS and the AI Act. If you have already read the two previous articles, most of the groundwork below is already done.

What already applies, briefly

What applies to most companies right now is not the heavy high risk requirements. It is the transparency requirements: users must be informed when they interact with an AI system, and AI generated content must be labelled as such. The obligations for general purpose AI models (GPAI) are already enforced, and the Danish authorities, with the Danish Agency for Digital Government as the lead supervisory authority, can demand documentation and issue fines of up to 15 million euro or 3% of global turnover. That sounds simple, but it still requires knowing which systems actually interact with users or generate content, and that is far from a given in an organisation where AI has appeared in many directions at once. The heaviest requirements, for high risk systems under Annex III, still hit the fewest companies, most companies are nowhere near where their AI use requires that classification. But the simpler use cases, chatbots, content generation, customer service, are where most companies actually stand, and where the overview is missing the most.

Why this is hard in practice

Few companies have a consolidated overview of their AI systems, and it is rarely because nobody has tried to build one. It is because AI today shows up everywhere at once. A department adopts a new SaaS tool with a built in AI feature without IT ever being asked. A vendor switches on an AI feature as an update to a system already in production. An employee uses a free AI service for a task nobody else knows about. The result is that AI systems in practice are scattered across procurement, IT, business units and shadow IT, with nobody tasked with keeping track of the full picture.

The speed of Nordic AI adoption far outpaces the organisation's ability to govern it. According to Deloitte's "State of AI in the Nordics 2026", 56% of Nordic organisations have now given more than 40% of employees access to approved AI tools, up from 37% just a year earlier, and within IT and cybersecurity 69% report that they have deployed AI at scale. The governance structure has not kept pace: EY's report "How Nordic Leaders Can Drive Responsible AI" from March 2026 shows that only 26% of Nordic CEOs are directly involved in strategy for new technology, compared with 49% globally, and points to fragmented accountability and a clear gap between perceived AI readiness and actual governance maturity.

The paradox is clear in Denmark. 48% of Danes have used generative AI within the past three months, the highest in the EU according to Eurostat, and 41% of Danish companies use AI in operations, twice the EU average, while 81% of Danish leaders expect a positive effect from the technology (BCG/Dansk Industri). The management infrastructure needed to secure compliance with the AI Act's requirements for human oversight, risk assessment and documented accountability has not kept up.

💡 You cannot classify what you have no overview of. Without a list of AI systems linked to business processes and data, the classification itself, high risk, GPAI or minimal risk, is guesswork from day one.

How Clariox helps

We do not chase AI systems one by one around the organisation. We build a living picture in Ardoq that links AI systems to the capabilities, applications and data they actually run on, so new systems become visible as they appear instead of being discovered at the next audit. That order matches what independent analysis of AI powered EA platforms points to as well: an AI implementation that holds up depends on a reliable, connected architecture foundation before the AI layer goes on top, not the other way round. This happens in three steps:

Phase 1: Reuse the foundation from NIS2 and DORA/PCI DSS

If the company has already mapped applications, business capabilities and ownership for NIS2 or DORA/PCI DSS, as we describe in the two previous articles in this series, the foundation is in place. The same map is reused to find the AI systems, instead of being drawn from scratch. If the mapping has not been done yet, the AI Act is reason enough on its own to start in the same place, because it reaches every industry, not just those already working on NIS2 or DORA/PCI DSS.

Phase 2: AI inventory and risk classification

With the foundation in place, we identify the AI systems on several tracks at once, instead of hunting for them one by one. We connect automatic data sources, including integrations to the major AI platforms such as Microsoft Copilot, OpenAI and Google Gemini, so the AI models and services already in use become part of the overview without manual work. What is not found in existing systems, we collect through Ardoq's automated broadcasts, short, recurring surveys sent directly in Ardoq, where each department owner has to confirm which AI tools are actually in use in their part of the business before it enters the inventory, human in the loop. The same applies to vendors: critical AI vendors are assessed formally and on an ongoing basis through the same mechanism, instead of once a year ahead of an audit. We build it in Ardoq, but the deliverable is yours, a single, up to date AI inventory with classification against the AI Act's categories, prohibited, high risk, GPAI or minimal risk, linked to the data and vendors each system depends on.

Phase 3: Documentation and ongoing monitoring

We structure data for the technical documentation and logging that Articles 11 and 12 require, including the requirement to retain system generated logs for at least 6 months for high risk systems, and for registration in the EU database for high risk systems once that becomes relevant. Every classification and assessment is approved by a named person with a written rationale, and because we never overwrite a previous assessment, only add a new one, we build up an audit ready history over time. The overview is kept current, so new AI systems appear as they are put into use, instead of being discovered when the 2027 deadline approaches.

By the end of the engagement, the company has one consolidated AI inventory in Ardoq: every AI system classified against the AI Act's risk categories, linked to the data, vendors and business capabilities it depends on, with a named owner and an audit ready history behind every assessment, and with the technical documentation for Articles 11 and 12 structured and ready to present if a regulator asks.

💡 Side benefit: If a company already uses the same foundation for DORA, NIS2 or PCI DSS, the AI inventory is typically half built already. Capabilities, vendors and data flows are the same, only the AI layer is missing to be connected.

Ready to get on top of the AI systems before the 2027 deadline becomes time pressure?

📅 Book a no obligation call at clariox.dk/contact

Clariox Advisory is an independent IT advisory firm and Ardoq partner, the only Ardoq focused partner in Denmark. This article is for informational purposes only and does not constitute legal or regulatory advice.

Figures and dates in this article are sourced from the European Commission's AI Act Service Desk, the Danish Agency for Digital Government, Deloitte's "State of AI in the Nordics 2026", EY's "How Nordic Leaders Can Drive Responsible AI", Eurostat, as well as BCG and Dansk Industri.

Troels Rendbæk Sørensen - CEO & Founder