Skip to content

EU AI Act‑ready AI use‑case intake: ship a small internal mini‑app (not policy PDFs)

When every team tests its own AI tool, you get risk, shadow IT, and constant stops from legal/security. A small internal ‘AI intake’ app captures use‑cases, does a lightweight risk triage, assigns owners, and stores evidence — so you can pilot fast with control.

Attila Arndt
Attila Arndt

Triple A Digital, Cologne · · 3 min read

Who it's for
IT, data protection and department leads in companies where every team tests its own AI tools.
What you'll be able to do
Set up one intake for AI ideas, sort each case roughly by risk, and start pilots with a clear approval.
As of
March 2026
TL;DR

In classic Mittelstand teams, AI rarely fails because of the model — it fails because of chaos: tools, data, owners, approvals. Build a small internal AI‑intake mini‑app that collects use‑cases, triages risk, assigns owners, and stores evidence. You get speed + control instead of “AI ban vs. wild growth”.

Primary source (quick but real)

The EU’s AI Act (Regulation (EU) 2024/1689) follows a risk‑based approach. Practically, that means you need a reliable way to capture AI use‑cases and handle them by risk/scope before scaling. The primary source is the EU AI Act, Reg. (EU) 2024/1689, on EUR‑Lex.

Not legal advice — this is an implementation/process play.

“AI in the company” turns into shadow IT

The common 2026 pattern: marketing uses three tools, sales uses two, HR adds another. Nobody can answer what data goes in, who is accountable, and how any of it is evaluated. Legal and security respond with stop signs (“please clarify first…”) — and everyone hates it.

Better: don’t “allow/ban AI”. Build a single intake flow.

Sprawl and stop signs — or one front door
Place
Without a front doorMarketing uses three tools, sales uses two, HR adds another.
With the intake appEvery AI idea has one place: a form as the single intake.
Accountability
Without a front doorNobody can answer who is accountable.
With the intake appOne owner per idea, plus reviewers from the business, IT and privacy.
Status
Without a front doorLegal and security respond with stop signs (“please clarify first…”).
With the intake appA status: submitted, in review, pilot, approved or rejected.
Evidence
Without a front doorNobody can answer what data goes in and how any of it is evaluated.
With the intake appA collected evidence set: links, contracts, DPIA artefacts, the approval log.
The five building blocks in the next section build exactly this right-hand column.

The minimal system: one front door for every AI idea

Goal: every AI idea has one place, one owner, a status, and an evidence set.

Five building blocks are enough.

Five building blocks of the intake app
  1. 01
    Use-case formAsks for purpose, users, data types, vendor or model, and the expected output.
  2. 02
    Lightweight risk triageSorts each case into low, medium, high or unknown.
  3. 03
    Owners and approvalsRecord who speaks up from business, IT, and privacy or security.
  4. 04
    Pilot gateSays tests may start — but only under clear rules.
  5. 05
    Evidence vaultCollects links, contracts, DPIA artifacts and the approval log.
Together they deliver the goal above: one place, one owner, a status, an evidence set.

You don’t need a perfect compliance engine. You need early signals.

Useful triage questions:

  • Does it process personal data or confidential information?
  • Does AI influence decisions about people (hiring, credit, access, scoring)?
  • Is the output external (customers) or internal (assistive)?
  • Any automated decisions without meaningful human control?
  • What controls exist (logging, human‑in‑the‑loop, prompt/policy guardrails)?

Result: you quickly see whether it’s a fast pilot or a governance project.

Checklist 1: AI use‑case intake (copy/paste)

AI intake: minimum questionnaire
  • Business goal (1 sentence) + expected impact (time/€, quality)
  • User group + accountable owner
  • Input data (public / internal / confidential / personal)
  • Output (internal / external) + consequence if wrong
  • Vendor/model (tool, hosting region, sub‑processors)
  • Integrations (Slack, CRM, files, email, ticketing)
  • Human‑in‑the‑loop: where must a person approve?
  • Logging/monitoring (what is stored, for how long?)
  • Pilot go/no‑go criteria

Checklist 2: AI‑intake mini‑app spec (shippable in 14 days)

Internal app: must / should / nice
  • MUST: form + single intake channel (no spreadsheets)
  • MUST: status board (Submitted / In Review / Pilot / Approved / Rejected)
  • MUST: owner + reviewer roles (business/IT/privacy/security)
  • MUST: evidence uploads + audit trail (who approved what when)
  • SHOULD: triage wizard (risk flags + default recommendations)
  • SHOULD: templates for common use‑cases (writing assist, support bot, summarization)
  • NICE: automated checks (PII detection, DLP, prompt policy)
  • NICE: export an “AI Use‑Case Dossier” (PDF/ZIP)

A realistic 14‑day plan

  • Days 1–2: define the form + roles/approvals
  • Days 3–5: status board + evidence vault + audit trail
  • Days 6–8: triage wizard + standard pilot rules (do/don’t)
  • Days 9–11: integrations (SSO, Slack/Teams, ticketing)
  • Days 12–14: dossier export + a 1‑page pilot playbook

Getting the AI‑intake mini‑app built

If you want to pilot AI fast — without losing control

Send me:

  • your top 5 AI use‑cases (short)
  • what data is involved (internal/PII/confidential)
  • who blocks/approves today (IT/privacy/security)

I’ll turn it into a small internal AI‑intake app that unblocks pilots, makes risk visible, and gives you an auditable trail.

Questions

Answered in brief

Should we ban AI until everything is sorted out?

Don’t allow or ban AI — build a single intake flow. Then every AI idea has one place, one owner, a status and an evidence set. That gives you speed and control instead of stop signs.

How do I spot early on that a use case is sensitive?

Five triage questions: does it process personal or confidential data? Does AI influence decisions about people? Is the output internal or external? Are there automated decisions without meaningful human control? What controls exist already? After that you know whether it’s a fast pilot or a governance project.

What does the intake app have to do as a minimum?

A form as the single intake channel, a status board from submitted to approved or rejected, owner and reviewer roles, and evidence uploads with an audit trail. The triage wizard, templates and automated checks come after that.

An example from my work

CommTrain: home page with a practice conversation
Co-founded · concept and development

CommTrain — practising difficult conversations

Practise difficult conversations by speaking instead of ticking boxes — with an AI counterpart and a review afterwards.

See the full case
Related

What I do in this area


Keep reading

Attila Arndt

Attila Arndt · Triple A Digital, Cologne

Is there a process like this in your company?

Pick a time that suits you. In the intro call, we'll work out which process is worth tackling first — and whether I'm the right person for it.

Free intro call (opens in a new tab)

Or email me directly: hello@tripleadigital.de · I reply within 48 hours.