Two weeks. That's how long it took us to implement a system that streamlines our use of AI at WorkTrips. We decided to implement Comparme's GovAI, a solution that helps manage the use of AI within the organization and supports preparation for the AI Act. The implementation itself took about two weeks. We now have not only a compliance assessment report but also the first signs that AI management is becoming a standard operating process.
Why did we do this?
The AI Act changes the way companies should approach the use of artificial intelligence. It's not just about whether an organization uses AI. It's also important to know:
- where AI is used,
- who is responsible for a specific solution,
- what is its purpose,
- what data is processed,
- what model does he use,
- what are the risks associated with its use,
- and whether it is possible to recreate the system's operation if necessary.
An organization should be able to identify its AI systems, classify them according to risk level, assign responsibility, conduct monitoring, and establish procedures for their use. In practice, this means one thing: AI is no longer just a tool used by individual employees or teams. It becomes part of the organizational infrastructure that must be consciously managed.
The first question was very simple: where do we actually use AI?
This was one of the most important starting points. As AI advances, it's easy to find a situation where one team uses an external model, another implements an agent, a third automates data analysis, and a fourth tests its own solution. Each of these scenarios can work well on its own, but the problem begins when the organization doesn't have a complete picture of the whole. This is where we needed more than a policy document.
Why GovAI?
To organize this area, we chose GovAI from Comparme. The solution acts as a layer between the organization and the AI models being used. Its architecture is independent of any specific model provider. However, the most important thing for us was not how many models it could be connected to, but what it offered at the management level. GovAI includes, among other things:
- AI agent registry,
- assigning an owner and risk level,
- scanning sensitive data,
- policies blocking unauthorized operations,
- human supervision,
- audit journal. This allows you to move from just using AI to controlling how AI actually works.
What did we do in these two weeks?
We built a registry of AI usage
The first step was to gather information about AI-based solutions. Each agent can be assigned an owner, a description of its activity, a risk level, and a basis for its use.We started classifying risks
The AI Act is based on a risk-based approach. Not every AI application is treated equally. Different requirements apply to simple tools supporting everyday work, different requirements apply to chatbots, and yet different requirements apply to systems that can influence important human decisions. GovAI divides applications into levels: minimal, limited, high, and unacceptable. This is important because governance should not rely on imposing the same rules on every AI application.We added a layer of data control
One of the more practical challenges of AI is sending information to models that shouldn't be there. Therefore, GovAI can detect and mask personal data before sending it to the model.
AI policy that actually does something
An AI policy specifies what can and cannot be used, what data can be transferred, and what rules apply to employees. However, the document itself doesn't block anything. In GovAI, policies can be enforced in real time. The system can block operations that violate the assigned rules.
What do we see after the first 30 days?
The technical implementation of this solution at our company, which offers clients the worktrips.com platform for managing business travel, took about two weeks. However, the coming weeks will reveal whether the system actually works as part of the organization. After the first 30 days, we're already seeing signs of operational maturity of the AI management system.
What's next?
AI will continue to emerge in future processes. It's almost inevitable. Therefore, our next goal is not to restrict its use, but to ensure that new applications are registered, assessed, and governed by appropriate policies from the outset.
Top comments (0)