blog

AI Act reveals the memory of an organization

Written by Brillian | Aug 5, 2026, 1:02:58 PM

At the beginning of August, the EU AI Act entered its next phase. In this article, I discuss the changes and why the AI ​​Act does not primarily require organizations to provide new reports or declarations, but rather requires them to understand and demonstrate their own actions.

What changed?

From August 2, 2026, the transparency requirements of Article 50 of the AI ​​Act came into effect. In practice, this means, for example, that the user must be told when they are interacting with AI. In certain situations, content produced or manipulated by AI must also be appropriately marked.

At the same time, many expected obligations regarding high-risk AI systems were postponed by the AI ​​Omnibus reform. For example, the requirements related to recruitment, lending and other high-risk use cases of Annex III were mainly postponed to December 2027. Many organizations were therefore given more time.

The deadline changed, not the administrative debt

However, the additional time given does not change the fact that the implementation of AI requires decisions, responsibilities, documentation and the ability to demonstrate afterwards how and why decisions have been made.

In this respect, the AI ​​Act is surprisingly similar to the GDPR, which regulates the processing of personal data. With the GDPR, it is not enough that the law (in Finland, tietosuojalaki, the Data Protection Act) is complied with and that the organization processes personal data in accordance with the law. The organization must also be able to demonstrate how the law is complied with. The same way of thinking is now clearly visible in the AI ​​Act. It is not just about whether AI is used responsibly. It is about the organization being able to demonstrate how the responsible use happens.

Transparency is a consequence of the organization aware of its own operations

Article 50 introduces a new type of transparency requirement for the use of AI. Organizations must disclose the existence of an AI solution, for example when a human interacts with an AI system or when content is generated or significantly modified by AI. The goal is for the user to understand when AI is involved and what its role is at any given time.

On the surface, the solution seems simple: add a notification to a chatbot or tag an image or response produced by AI. In reality, the requirement goes much deeper than a notification.

For an organization to operate transparently, it must first know itself where AI is used, for what purpose it is used, what kind of content or decisions are produced with it, and who is responsible for their use. Transparency therefore does not appear from a mere notification to the customer, but from the organization having sufficient understanding of its own operations.

Organizational amnesia as a diagnosis

There is an interesting concept: institutional (or organizational) amnesia. It refers to a situation where an organization can no longer explain why a decision was made at the time. Amnesia rarely happens overnight for an organization. It happens gradually. An exception is approved in a hurry, a process is changed slightly, or a decision is made in a Teams meeting. It may seem so insignificant at the time that it is not even worth writing it down. At that moment, everyone understands why this is done, so justifications are not seen as necessary. A year later, the process still exists, but no one can answer the simple question: why was this done this way, or what is the goal of this? People have not forgotten, but the organization has lost its memory because the background of the decisions was never recorded.

I have served as a designated data protection officer (DPO) [SN1] in a couple of organizations, and have recently had several discussions about the decisions related to the entry into force of the GDPR in 2018, which were made in connection with audits. Some of the decisions related to processes now feel outdated and even contrary to common sense. However, the decisions themselves are easily justifiable because their backgrounds were carefully documented. Of course, that does not mean that the operating model should not be changed and developed. This is where governance is at its best: the justifications for decisions do not disappear, even if people change. The significant threat of sanctions from GDPR certainly accelerated this development, but the result has been valuable for organizations in other ways as well.

Article 50 does not specifically regulate or impose governance: it makes it visible why it is needed

When an organization needs to openly explain where AI is used, on what basis decisions are made, or how risks are managed, good intentions alone are no longer enough. Evidence is needed that the operating models actually exist.

Perhaps this is where the AI ​​Act’s silver lining lies. It not only regulates the use of AI, but also forces organizations to make visible the knowledge that previously lived in people’s heads, in email threads and Teams conversations. Good governance does not arise because of regulation, but regulation can push organizations to build it.

 

Would you like to discuss with Salla Niskanen? Reach out at salla.niskanen@brillian.fi or on LinkedIn.