KlarComply
HomeKnowledge › Approving AI tools

An approval process for AI tools: decide, rather than prohibit

An approval process is not bureaucracy. It is the opposite of it: one rule replacing a hundred separate decisions. It is also the only effective remedy for shadow AI — provided it is faster than the route around it.

By , Founder of KlarComply · Reviewed on

Infographic: The approval process: four steps against shadow AI — New AI tools will arrive either way — the only question is: controlled or covert.
The key points of this article as a graphic — feel free to share or download it.

Why a process and not a list

Many companies start with a list of permitted tools. That works for about four weeks. Then a new tool appears that somebody needs for their work, it is not on the list, and they use it anyway — because nobody knows who they would have asked.

A process answers three questions permanently. Who asks whom? On what basis is it decided? And how long does it take? Miss any one of those answers and shadow AI appears. The third is the one most often forgotten, and it is the most important.

The rule everything hangs on: the turnaround

Commit to a response time and keep to it. Ten working days is a workable figure; five is better. Anyone who waits more than three weeks for an answer will not submit a request next time. They will quietly open a personal account.

A process with no stated turnaround behaves, in practice, exactly like a ban — with the difference that you believe yourself to be covered.

Three lanes: not every tool needs the same scrutiny

A single full assessment for every tool creates a queue. Sort the requests first instead.

LaneWhat goes in itProcedure
Blanket approvalAI features inside software already assessed, where no new data flows arise — for example drafting help inside the office suite you already runa single decision in principle, an entry in the inventory, no individual requests
Short assessmentTools with no personal data and no confidential content, for example image generators used for illustrationssteps 1, 2, 5 and 7 of the checklist, usually under thirty minutes
Full assessmentAnything involving personal data, customer records, pricing, applications, or a connection to internal systemsall seven steps, with data protection consulted

The seven checks

1. Purpose and alternative

What exactly is the tool for, and is there already an approved tool that does it? The second part resolves a surprising share of requests on its own. In many companies three tools run for the same task, because three departments went looking independently.

2. Categories of data

What data are to go in? Do not answer “text”. Answer in categories: customer names, contract data, application documents, pricing calculations, source code, health data. That answer determines whether lane two or lane three applies, and whether data protection has to be involved.

3. Contract and account

Is there a business tier? Is a data processing agreement offered? Who is the counterparty? Are inputs used to improve models, and can that be switched off? Where are the data held? The data protection side is set out on ChatGPT at work.

4. Confidentiality

Can trade secrets end up in it? If so, confidentiality has to be assured contractually — otherwise you put at risk the requirement in Directive (EU) 2016/943 that the information be subject to reasonable steps under the circumstances to keep it secret. Check as well whether your customer contracts prohibit disclosure to third parties without consent. That clause appears in more contracts than most companies expect.

5. Risk class under the AI Act

Prohibited practice, high-risk, transparency duty or minimal risk? What decides it is the purpose of use, not the tool. The same language model can be unremarkable for drafting text and high-risk for pre-sorting job applications. The method is on classifying AI risk. Record the class and the reasoning — the reasoning is the evidence.

6. Transparency duties

Does the tool produce content that goes out into the world? Images, voices, video, chat replies? Then settle before approval who applies the disclosure and what it says. Ready-made labels in three languages are free on our AI labels page. The scope and the limits of the duty are on labelling under Article 50.

7. Operation and exit

Who administers the accounts? What does it cost? What happens to the data if you cancel — and how do you get your content out? The exit part is almost always skipped and almost always surfaces eventually.

Who decides what

Clear allocation prevents endless loops. A model that holds up in companies between twenty and two hundred and fifty people:

RoleTask in the approval process
Requestercompletes the form, describes the purpose and the data categories
AI leadruns the assessment, decides, records — see appointing an AI lead
Data protectionconsulted in lane three, may object, does not decide
ITchecks integration, accounts, access rights
Managementdecides where cost exceeds a defined threshold and on any high-risk classification
Employee representativesinvolved where the tool is capable of monitoring conduct or performance — see AI and employee representation

The request form — nine fields

Any longer and it does not get filled in. One page, ideally a form on the intranet.

  1. Name of the tool and the provider
  2. Who is requesting it, for which area
  3. The specific purpose, in one sentence
  4. Which categories of data are to go in
  5. Is there already an approved tool for this? If so, why is it not sufficient?
  6. Does the tool produce content for publication?
  7. Cost and contract term
  8. Number of intended users
  9. Desired start date

The field that saves the most work

Field 5. Asking whether an approved tool already exists disposes of a substantial share of requests before any assessment is needed — and it saves licence costs that otherwise nobody notices.

The decision: four possible outcomes

Every decision goes into the AI inventory: tool, purpose, class, reasoning, date, decision-maker. Refused tools go in as well — otherwise the same request arrives again in six months and is assessed again from scratch.

Three cases as they actually occur

Case 1: an image generator for a trade stand

Marketing wants to generate imagery. No personal data are involved and no confidential content. Lane two, short assessment. Only two points matter here: the rights of use in the generated images under the provider's terms, and the disclosure obligation as soon as the imagery becomes photorealistic. Approved on condition that every published image carries a disclosure. Processing time: half an hour.

Case 2: a note-taking assistant for customer calls

Sales wants to record and summarise conversations. This is squarely lane three: personal data, recording of conversations, and the possibility of evaluating how someone conducts a call. To settle: the processor contract, the legal basis, consent of the other party to the recording, the retention period — and involvement of the employee representatives, where a body exists, because performance data can be derived from such recordings. Realistic processing time: two to four weeks. Tell the requester that on day one, not on day twenty.

Case 3: an AI feature that arrives by update

A program you already run acquires an AI feature. The decisive point is not the feature. It is the question: does a new data flow to a different provider arise? If processing stays with the existing counterparty and within the existing terms, a decision in principle with an inventory entry is enough. If data now flow to a third-party model, it is a new tool and needs the full assessment — even though nobody installed anything.

The assessment record, as a table

Record the outcome in exactly this form. It is simultaneously your inventory entry and your answer in the next supplier questionnaire.

Withdrawal: the route back

Approvals are not permanent. Consider withdrawing one where the provider changes its terms to your detriment, where a security incident becomes known, where the contractual basis falls away, or where the tool is simply no longer being used. The last of those is the most common and the easiest: unused licences cost money and enlarge the attack surface.

A withdrawal needs the same care as an approval: reasons, a date, notice to the users, and a statement of what they should use instead.

What you do not need

Introducing it in a week

  1. Day 1: settle the checklist and the form, define the lanes.
  2. Day 2: allocate responsibilities in writing, set the turnaround and commit to it.
  3. Day 3: finish the stocktake and send every tool already in use back through the assessment retrospectively — with an amnesty for the past.
  4. Day 4: write the rule into the AI policy, see writing an internal AI policy.
  5. Day 5: present it to the team: where the form is, who decides, how long it takes. Those three sentences decide whether it works.

Whether the foundations for it are in place takes two minutes to check with the free quick check.

One note for companies outside the EU

Add a single field to the form: will the output of this tool be seen by, sent to or acted on by people in the Union? Under Article 2 of the AI Act that is what brings a third-country deployer into scope, and it is the question you would otherwise have to reconstruct months later from memory. Asking it at the point of approval costs nothing and answers itself.

Frequently asked questions

Is an approval process for AI tools required by law?

Not expressly. It is the most practical way to implement the deployer duties in the AI Act and the organisational measures required by Article 32 GDPR, and it is the most effective remedy for shadow AI. Supplier questionnaires now ask for it by name.

How long may an approval take?

Commit to a turnaround and keep to it. Ten working days is workable, five is better. If it takes more than three weeks, people route around the process and open personal accounts. At that point you have moved the problem, not solved it.

Does every AI feature in existing software need its own approval?

No. Where an application already assessed acquires an AI feature and no new data flows arise, a single decision in principle with an inventory entry is enough. Where data now flow to a different provider, it is a new tool.

Who should decide on approvals?

One named individual, normally the AI lead. Data protection and IT are consulted and may object but do not co-decide. Management decides on high cost and on any high-risk classification, and employee representatives are involved where the tool is capable of monitoring performance.

What do we do with tools already in use without approval?

Send them back through the assessment retrospectively, with an express amnesty for the past. Without that assurance nothing gets reported and your stocktake stays incomplete. From a clearly stated date, the process applies.

Do we need software for the approval process?

In most companies, no. A one-page form and a spreadsheet carry you well past a hundred employees. A tool does not replace a clear allocation of responsibility or a turnaround you have committed to — and those are what processes fail on.

What does the approval record have to contain?

Tool, provider and contracting entity; the purpose in one sentence; the lane; data categories; whether a processor contract exists and from when; whether training use is disabled; the risk class with reasoning; whether a disclosure is required and who applies it; the decision with conditions, date and decision-maker; and the date of the next review.

Where does your company stand?

The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.

Start the quick check — free
Read on AI literacy obligation → Building an AI inventory → Labelling AI content (Art. 50) → The AI Act for SMEs → Writing an AI policy → AI in hotels → AI in the beauty salon → Appointing an AI lead → ChatGPT at work and the GDPR → Finding shadow AI → AI and employee representation → Classifying AI risk → The AI supplier questionnaire → Customer data in an AI tool → Penalties under Article 99 → Trade secrets and AI tools → AI in physiotherapy practices → AI in dental practices → AI in tax and accounting firms → AI in hair salons → AI in advertising agencies → AI for estate agents → AI in car repair shops → AI in trades businesses → AI in law firms → DPO requirements → Records of processing → DPA (Art. 28) → Data breach & 72 hours → GDPR staff training → US tools & transfers →
Sources:
Article 26 EU AI Act — obligations of deployers
Article 50 EU AI Act — transparency obligations
Article 32 GDPR — security of processing
Directive (EU) 2016/943 — protection of trade secrets
Regulation (EU) 2024/1689 — official consolidated text, EUR-Lex
Reviewed on 2 August 2026 · Reflects the Digital Omnibus · This article is general information and not legal advice.