
Artificial intelligence is already in use in many Belgian companies today: among other things, for customer service, financial administration, document processing, marketing, reporting, planning and cyber security.
According to the most recent Belgian figures (information in NL/FR), in 2025 approximately 24% of SMEs were using AI. Among medium-sized enterprises, this proportion rose to 54.5%.
It's an understandable trend. AI can speed up repetitive tasks, process large amounts of information and support employees doing tasks that used to be very time-consuming. For companies, this can lead to efficiency gains, improved service and more scope for strategic work.
At the same time, AI is not just an ordinary software feature. The technology is capable of processing personal data, influencing decisions, recording confidential information and generating incorrect output. The company remains responsible for the way in which it uses AI, even if the system was developed by an external supplier.
The following five key points will help you to integrate AI into your day-to-day operations in a responsible manner.
Find out which AI is used in your company
One of the initial challenges is the uncontrolled use of AI by staff. Employees might be using public chatbots such as ChatGPT or Google Gemini to summarise texts, write emails, analyse contracts or generate code.
This practice is not necessarily problematic. However, it becomes risky when the company does not know which tools are being used, what data are being entered and who is checking the results. Furthermore, existing software may have embedded AI functionalities without this being regarded internally as a separate AI application.
Companies that use an AI system in their professional activities are, in principle, what are known as ‘data controllers’. This means that they must consider not only the purchase of the tool, but also how it will actually be used within their organisation.
Practical recommendations:
Create a simple AI inventory. For each application, note:
- which tool is used;
- for what purpose;
- what data are entered;
- which people or processes are affected;
- who is responsible internally;
- what checks are required before use.
You should also include any use of AI that did not go through the official procurement procedure. Without an understanding of current usage, it is difficult for a company to introduce proportionate rules.
Protect personal data and confidential information
A prompt can contain more than just a standard search query. Employees may unwittingly enter names, customer details, staff information, financial figures, contracts or trade secrets.
As soon as personal data are processed, the GDPR applies and continues to apply, even where this processing is carried out with the aid or support of AI. Among other things, the company must be able to justify why the data are being processed, whether the processing is necessary, how long the data will be kept and what security measures have been put in place.
The GDPR and the AI Act complement one another. The fact that an AI application falls within a limited risk category does not, therefore, mean that the privacy obligations cease to apply. The principles of lawfulness, purpose limitation, data minimisation, accuracy, transparency and security remain relevant.
Trade secrets, too, merit special attention. A company may not know what data a public AI service stores, who has access to the input, or whether this input is used to improve the service or the models.
Practical measures:
Enter a data classification for AI use. Determine what information:
- may be entered without risk;
- may only be processed in an approved operational environment;
- must first be anonymised;
- must never be entered into an external AI tool.
You should also check the data retention, model training, sub-processor and hosting settings. A good AI policy should not only specify what is prohibited, but also offer a practical and safe alternative.
Let AI provide support, but don’t let it make decisions blindly
AI output can sound convincing yet still be incorrect. A system may produce incorrect figures, non-existent sources or misinterpretations. Furthermore, in sensitive processes, bias in the data or the model can lead to unequal treatment.
This risk is particularly high when AI is used in recruitment, staff appraisals, promotions, granting credit or access to services. Depending on the function and context, such applications may be subject to the stricter rules governing high-risk AI.
In this context, human oversight means more than just formal retrospective approval. An employee who simply copies the AI output without making their own assessment offers little protection. Human intervention must be genuinely meaningful.
Recent Belgian case law shows just how quickly the careless use of AI can have tangible consequences. In a case where AI was used to draft legal documents, it transpired that the sources and case law cited did not exist. The problem was not that AI was used, but that the output was not properly checked.
Practical measures:
Determine in advance for which applications human supervision is required. At the very least, consider:
- legal, tax or financial advice;
- communication with customers or public authorities;
- HR decisions;
- decisions with significant financial implications;
- critical safety instructions;
- external publications containing factual claims.
A simple verification protocol may suffice: check the facts, verify the sources, assess their suitability for the specific context and record who approved the output.
Don’t forget about employees and wellbeing at work
AI can support employees, but it can also affect their autonomy and the way they organise their work. Think of systems that measure performance, allocate tasks, screen job applicants or monitor work rates.
When it comes to AI in HR, it is not only privacy legislation that is relevant. Information and consultation obligations, discrimination risks and regulations concerning wellbeing at work may also play a role. Depending on the circumstances, the works council, the OHSC or other employee representatives, among others, must be involved.
When introducing new technology, it is also important to consider potential psychosocial consequences, such as technostress, increased work intensity, permanent availability or the feeling of being under constant surveillance.
Emotion recognition in the workplace is also a clear no-go. The use of AI to deduce the emotions of employees or job applicants is, in principle, prohibited, subject to limited exceptions for medical or safety purposes.
Practical procedure:
Assess AI applications for HR in collaboration with your organisation’s HR, legal, IT, health and safety departments and the DPO.
In this context, ask at least the following questions:
- Which decision affects the system?
- Are employees or job applicants profiled?
- Can the application discriminate indirectly?
- Who can overrule the output?
- Can those affected have incorrect data corrected?
- What consultation and information requirements apply?
- What impact does the system have on workload and autonomy?
Make contracts and governance as practical as the technology itself
AI is not usually developed entirely in-house. Companies use AI via cloud platforms, software licences, APIs and existing business applications. As a result, part of the control lies with the supplier.
A general provision such as ‘no AI without prior approval’ sounds protective, but in practice it is often too broad. After all, AI may be integrated into a supplier’s standard service. It is better to distinguish between low-risk use, such as internal support, and use where AI directly affects customer communications, decisions or transactions.
When assessing a supplier, factors such as data usage, model training, security, sub-processors, intellectual property, audit rights, incident reporting, model changes and termination all must be taken into account.
The same logic applies internally. AI governance does not necessarily have to result in a cumbersome new supervisory body. However, responsibilities must be clearly defined: who approves new applications, who manages the inventory, who handles incidents and who reports to management?
The AI Act also requires measures to support AI literacy within the organisation. The law does not prescribe a specific training programme or a particular individual certificate, but training and practical guidelines must be appropriate to the role, experience and context of the staff concerned.
Practical procedure:
Establish a concise AI framework comprising:
- a person responsible for AI governance;
- a list of approved tools;
- rules on data use;
- an approval procedure for sensitive applications;
- a mandatory human checkpoint;
- an incident procedure;
- role-based training.
Additional safeguards are required for AI systems that are capable of taking action on their own – for example, sending (email) messages, modifying data or initiating transactions. Implement access restrictions, approval thresholds, logging and an effective stop function.
Conclusion – Start today with a proportional framework
The European AI regulations are risk-based. Not every AI application requires a comprehensive compliance project, but every organisation needs to know what it is using and what the implications of this use might be.
A good initial approach consists of four steps:
- identify existing AI applications and experiments;
- assess the impact on individuals, data and business processes for each application;
- set out clear rules on approval, data use and human oversight;
- review supplier contracts and existing privacy, HR and IT processes.
So there is no need to curb AI. The companies that derive the greatest value from it are unlikely to be those that use the technology with the least restraint, but rather those that combine speed with clear accountability.
A brief AI governance or risk assessment can quickly reveal where the biggest gaps lie and where the most feasible improvements can be made. In this way, AI does not become a separate legal project, but a manageable part of broader business operations.