May 19, 2023
Advancing Your Accounting Career: Benefits and Strategies
Explore the perks of an accounting career – stability, competitive pay, and growth prospects. Learn how to excel in this dynamic field.
Artificial intelligence is becoming part of everyday business operations, from drafting emails and analysing documents to recruiting employees, communicating with customers and assessing financial risk.
The EU Artificial Intelligence Act, Regulation (EU) 2024/1689, establishes a legal framework for the development, provision and professional use of AI systems. It does not prohibit ordinary business use of artificial intelligence. Instead, the requirements depend mainly on how the technology is used and the level of risk involved.
With the main provisions and transparency requirements applicable since 2 August 2026, businesses should identify which AI systems they use, understand how those systems affect people and introduce appropriate safeguards. Further details are available from the European Commission.
The AI Act may apply to almost any organisation that develops, offers, imports, distributes or professionally uses an AI system. A business using tools such as ChatGPT, Microsoft Copilot or Gemini, including AI functions built into accounting or recruitment software, will generally be considered a “deployer” and remains responsible for how the system is used.
The Act may also affect companies established outside the European Union if they offer AI systems in the EU or if the output produced by their systems is used within the EU.
The risk category of an AI system is determined mainly by its intended purpose and the way it is used, rather than by the technology or product name alone.
| Business use | Likely classification |
| Correcting the grammar and style of an email | Minimal risk |
| Summarising an internal report | Minimal risk |
| Operating a customer-service chatbot | Transparency obligations |
| Generating advertising images | Possible labelling obligations |
| Ranking or rejecting job applicants | Potentially high risk |
| Recognising employees’ emotions in the workplace | Generally prohibited |
The same AI technology can therefore fall into different categories depending on the context in which it is deployed.
Certain uses of AI are prohibited because they create an unacceptable risk to people’s rights and safety. These include specific forms of manipulative AI, social scoring and the exploitation of certain vulnerabilities. AI-based emotion recognition in the workplace is also generally prohibited, except in limited medical or safety situations. These restrictions have applied since 2 February 2025.
AI systems may be classified as high-risk when used in sensitive areas such as recruitment, employee management, education, creditworthiness assessments, essential services and critical infrastructure.
Not every AI-assisted process in these areas is automatically high-risk. For example, an HR tool that extracts names and qualifications from CVs may be treated differently from a system that automatically ranks and rejects candidates.
High-risk systems face more extensive requirements concerning risk management, documentation, traceability, human oversight, accuracy and cybersecurity.
Under the updated implementation timetable, rules for high-risk systems in areas listed in Annex III, including employment, education and credit, will apply from 2 December 2027. Rules for high-risk AI incorporated into certain regulated products will apply from 2 August 2028. The European Commission’s guidance on high-risk AI systems provides further information.
Since 2 August 2026, specific transparency requirements have applied to certain AI systems. When customers communicate directly with a chatbot or virtual assistant, they should be informed clearly and promptly that they are interacting with AI, unless this is already obvious.
Deepfakes and certain AI-generated or substantially manipulated content may also need to be disclosed. More information is available in the European Commission’s guidance on AI-generated content.
Common tools for text editing, translation, document summarisation and idea generation are generally considered minimal risk. Businesses must still consider data protection, confidentiality, cybersecurity, copyright and employment legislation.
Since 2 February 2025, providers and deployers have been required to promote an appropriate level of AI literacy among people using AI on their behalf.
Employees do not need to become technical experts. Training should reflect their responsibilities, experience, the system being used and its possible impact on affected individuals.
Employees should understand that AI output can be inaccurate, important results require human review and confidential information must not be entered into unauthorised systems. They should also know when AI content needs to be disclosed and how to report an incident.
Businesses should retain appropriate evidence of completed training.
Identify approved systems and public tools employees may use independently. Record their purpose, provider, data processed and influence on decisions concerning individuals.
For each system, establish whether the business acts as a provider, deployer, importer, distributor or manufacturer of a product incorporating AI. The applicable responsibilities will depend on this role.
Consider whether the system supports employment decisions, credit assessments, biometric analysis, customer communication or public content. These uses may require a more detailed assessment.
The policy should identify approved tools and permitted uses, information that may be entered, situations requiring human review and the process for approving new systems. It should also cover content labelling, incident reporting and responsibility for final decisions.
Training should reflect the risks encountered by different departments. Marketing teams may need guidance on content labelling and copyright. HR teams should understand discrimination risks and human oversight. Accounting and finance employees should focus on confidentiality, professional secrecy and the handling of client information.
Businesses should request clear information about a system’s intended purpose, risk classification, limitations, data practices, security measures and compliance documentation. A general statement that a product is “AI Act compliant” should not replace proper due diligence.
Professional-services firms regularly process financial records, contracts, personal information and commercially sensitive documents. Uploading such information to a public or unauthorised AI tool may create risks under data-protection rules, confidentiality obligations and professional standards.
Businesses should use approved corporate systems, restrict access according to employee responsibilities and anonymise information where appropriate. Original client documents should not be uploaded to public AI tools without a valid basis, appropriate safeguards and internal approval.
Human oversight also remains essential. AI may support research, drafting and analysis, but the responsible professional should verify the accuracy, relevance and completeness of the final result.
For most businesses, the AI Act does not mean giving up tools such as ChatGPT or Copilot. The greater practical risk is using AI without knowing which systems are in use, what information employees enter or whether automated results influence important decisions about people.
A sensible starting point is to create an inventory of AI systems, assess how they are used, establish clear internal rules and provide practical employee training. These measures can help businesses benefit from AI while protecting confidential information, maintaining human oversight and preparing for the remaining stages of the EU AI Act.
TGS Bulgaria can support businesses in reviewing their internal processes and assessing the financial, organisational and compliance implications associated with the professional use of artificial intelligence.