AI Act & Augmented Consulting: How to Navigate Towards Secure Artificial Intelligence Adoption?
Published on 29 May 2026
Artificial intelligence is already present in HR and Finance functions. Content creation, data analysis, chatbots, candidate scoring, task automation: its uses are rapidly multiplying.
But this acceleration raises a crucial question: how to secure these uses without hindering innovation?
With the gradual entry into force of the AI Act, companies must now structure their approach. The challenge is no longer solely technological: it also becomes regulatory, organizational, and human.
AI Act 2026: Deciphering a New Framework of Trust
The AI Act, adopted by the European Parliament on July 12, 2024, marks a historic turning point: it is the world’s first legislation to comprehensively regulate artificial intelligence. Rather than regulating the technology itself, Europe has chosen to regulate its uses based on the risk they pose to citizens. Its objective is to promote human-centric, trustworthy AI that respects fundamental rights.
Concretely, the AI Act functions as a “product standard” applied to artificial intelligence. Designers and providers of AI solutions are placed at the heart of digital compliance and will have to demonstrate that their tools meet certain requirements before commercialization, according to rules based on the risks associated with their uses. The text aims in particular to strengthen security, the protection of fundamental rights, health, the environment, and trust in AI systems.
For businesses, the AI Act also becomes a reference framework for structuring the acquisition and deployment of AI solutions and complementing the GDPR. Where the GDPR primarily acts on the protection of personal data, the AI Act intervenes earlier in the design, operation, and supervision of artificial intelligence systems.
“AI must be a tool for people and a force for good in society, with the ultimate goal of increasing human well-being.”
EU AI Act, Regulatory Basis 2026
AI Act: Not All Uses Have the Same Level of Risk
One of the main contributions of the AI Act is to introduce a risk-based approach. Therefore, not all AI uses are subject to the same obligations. “Minimal risk” systems remain largely unregulated. Conversely, certain uses considered “high-risk” will have to comply with strong obligations regarding documentation, transparency, human oversight, data quality, and traceability. Systems deemed “unacceptable risk” may even be prohibited.
For HR and Finance departments, this framework becomes a true operational compass. In projects conducted around HR functions, for example, very different situations are observed. The use of generative AI to assist teams in drafting job descriptions or HR content generally falls under a limited risk level, with primarily transparency obligations regarding AI use. Conversely, certain tools may involve higher levels of vigilance. An HR chatbot capable of answering employee questions may present a moderate level of risk, particularly depending on the data handled and its role in access to internal information.
Other use cases fall into more sensitive categories under the regulatory framework. Candidate scoring tools or internal mobility assistance tools can, for example, be considered high-risk systems when they participate in recruitment or evaluation processes. Similarly, any algorithm likely to influence a decision related to promotion, performance evaluation, or employee compensation must be given particular attention.
This gradation allows compliance efforts to be concentrated where human impact is strongest. The bar rises as soon as the human impact is direct, and a structured analysis of AI uses within organizations becomes paramount.
“Not all AI uses involve the same level of risk. An AI that writes content does not have the same impact as an algorithm that influences a promotion or a hiring decision.”
2026: A New Regulatory Stage for Businesses
Even if certain provisions of the AI Act have already gradually come into force, 2026 will mark an important milestone. From August 2, 2026, the rules will become much more concrete, especially for so-called “high-risk” systems. Developers, publishers, integrators, suppliers, and user companies will all be concerned.
Organizations will notably need to be able to identify their AI uses; qualify their risk level; document certain systems; implement appropriate controls; and ensure human oversight where necessary.
The AI Act also provides for the establishment of “regulatory sandboxes,” i.e., environments allowing AI solutions to be tested in a controlled setting before their large-scale deployment. For businesses, this represents an interesting opportunity: to experiment more serenely, while anticipating regulatory requirements.
“The AI Act does not aim to prevent companies from innovating. It aims to provide them with a framework to innovate more safely, more transparently, and more sustainably…”
From ‘Shadow AI’ to Controlled Adoption: Finding the Right Stance
Today, faced with the AI surge, companies often adopt three postures, sometimes risky. First, total prohibition, which often leads to “Shadow AI”: employees secretly use unsecured public tools to draft emails or analyze Excel files. Conversely, free use without a framework creates technological silos and risks of sensitive data leaks. Finally, massive investment in licenses without a strategic vision often leads to a lack of ROI and explainability of decisions.
The current challenge is to move beyond these extremes to adopt an organized adoption posture. AI is already here; the issue is to define which uses are authorized, on what data, and with what human validations. This is where Althea’s expertise comes in to transform this diffuse presence into a structured competitive advantage.
“The challenge is neither to block AI nor to let it spread without a framework. It is about organizing its adoption to make it a secure lever for performance.”
The Role of IT Consulting Firms & ESNs in This New Regulatory Framework
With the proliferation of artificial intelligence solutions in companies and the gradual entry into force of European regulations such as the AI Act or the Cyber Resilience Act (CRA), organizations must structure their AI uses while controlling the associated risks. In this context, IT consulting firms and ESNs can support companies in securing the integration of these technologies into their information systems.
Support generally begins with a scoping phase aimed at mapping existing or planned AI uses within the company. This analysis helps identify use cases, tools used, and data handled, especially when sensitive. The different use cases can then be qualified against the risk levels defined by the AI Act to anticipate associated regulatory obligations.
Consulting firms can also help companies structure appropriate AI governance, by defining internal usage rules, validation processes for new use cases, and control frameworks to ensure transparency and human oversight where necessary.
Another important aspect concerns raising awareness and training business and HR teams on issues related to AI use: understanding the regulatory framework, managing algorithmic biases, transparency of automated decisions, and data protection.
Finally, the support also aims to identify and develop relevant and controlled use cases. In the HR domain, this may concern topics such as recruitment, skills management, GEPP, payroll data analysis, or talent management tools, ensuring that these solutions remain compliant with regulatory requirements and transparency principles.
Althea’s Support: Towards High-Performing and Compliant AI
In this context, Althéa can support companies through a structured methodology that both secures existing uses and builds a coherent AI trajectory.
Map existing AI uses: The first step is to conduct a diagnostic of AI uses already present in the organization. The objective is to identify officially used or more informal tools, data handled, populations concerned, and “shadow AI” practices.
This step is essential, as many companies already use AI without always having a clear vision of what actually exists.
Thanks to its dual business and data expertise, Althéa is able to engage with HR, Finance, business teams, and IT departments to identify sometimes very different uses: HR assistants, recruitment tools, payroll analysis, skills management, process automation, or generative AI.
Qualify risks with regard to the AI Act: A second step consists of qualifying each use with regard to the AI Act.Not all use cases present the same level of risk. An AI used to draft HR content does not require the same level of control as a candidate scoring algorithm, internal mobility, or compensation analysis.
This analysis allows for prioritizing the most sensitive topics and anticipating compliance obligations.
Althéa can add value at this stage thanks to its knowledge of HR, Finance, and Talent processes, as well as its understanding of data, bias, traceability, and human oversight issues.
Structure governance and usage rules
Once risks are identified, the challenge is to structure clear governance. This can involve defining usage rules, clarifying roles between HR, IT, compliance, and business units, establishing validation circuits, or defining which data can or cannot be used.
The objective is to avoid inconsistent uses, poorly explainable decision-making, or the sharing of sensitive data in unvalidated tools.
Althéa can support this step by helping companies formalize simple, pragmatic rules adapted to their operational reality.
Train teams and support change: AI is already present in employees’ daily practices. The challenge is therefore not only to deploy tools but also to ensure that teams understand authorized uses, associated risks, and best practices to adopt.
Training HR, Finance, business, and management teams becomes essential to limit “shadow AI” practices and promote more controlled adoption.
Thanks to its business roots, Althéa can adapt these awareness actions to the concrete challenges of the populations concerned, with examples close to their daily lives.
Build useful, realistic, and compliant use cases: Finally, the last step is to develop use cases that truly create value.
On topics such as payroll, skills, recruitment, GEPP, pay transparency, or talent management tools, the objective is to build solutions that provide a concrete benefit while remaining compatible with the regulatory framework.
Althéa’s interest is precisely to be able to link regulation, business challenges, and operational solutions.
The idea is not to achieve compliance for compliance’s sake. It is about transforming a regulatory obligation into a lever for structuring, securing, and performance.
“We transform regulatory constraints into a governance framework that finally unleashes the potential of artificial intelligence.”
Conclusion
The AI Act is, above all, a reference framework to help companies better choose their tools, better regulate their uses, and better protect their employees.
The organizations that will succeed tomorrow will not necessarily be those that use the most AI, but those that know how to find the right balance between innovation, performance, risk management, and trust.
To go further…
Discover all regulations in force in 2026 Act via The AI Act Explorer:
Pour offrir les meilleures expériences, nous utilisons des technologies telles que les cookies pour stocker et/ou accéder aux informations des appareils. Le fait de consentir à ces technologies nous permettra de traiter des données telles que le comportement de navigation ou les ID uniques sur ce site. Le fait de ne pas consentir ou de retirer son consentement peut avoir un effet négatif sur certaines caractéristiques et fonctions.
Fonctionnel
Always active
L’accès ou le stockage technique est strictement nécessaire dans la finalité d’intérêt légitime de permettre l’utilisation d’un service spécifique explicitement demandé par l’abonné ou l’utilisateur, ou dans le seul but d’effectuer la transmission d’une communication sur un réseau de communications électroniques.
Préférences
L’accès ou le stockage technique est nécessaire dans la finalité d’intérêt légitime de stocker des préférences qui ne sont pas demandées par l’abonné ou l’internaute.
Statistiques
Le stockage ou l’accès technique qui est utilisé exclusivement à des fins statistiques.Le stockage ou l’accès technique qui est utilisé exclusivement dans des finalités statistiques anonymes. En l’absence d’une assignation à comparaître, d’une conformité volontaire de la part de votre fournisseur d’accès à internet ou d’enregistrements supplémentaires provenant d’une tierce partie, les informations stockées ou extraites à cette seule fin ne peuvent généralement pas être utilisées pour vous identifier.
Marketing
L’accès ou le stockage technique est nécessaire pour créer des profils d’internautes afin d’envoyer des publicités, ou pour suivre l’utilisateur sur un site web ou sur plusieurs sites web ayant des finalités marketing similaires.