1. Introduction to the EU AI Act
The EU AI Act is legislation designed to regulate the use of AI within the European Union. It sets out strict requirements regarding transparency, security and ethical standards that organisations must meet in order to use AI systems lawfully.
2. The Role of ITSM and ITIL Practices
ITSM and ITIL practices provide a structured approach to the management of IT services. These methods help organisations optimise their IT processes and ensure that all compliance requirements are met. Here are some key areas in which ITSM and ITIL practices support compliance with the EU AI Act:
Transparency and documentation:
ITIL practices promote comprehensive documentation of all IT processes and services. This helps to ensure the necessary transparency and provide all relevant information required for compliance with the EU AI Act.
Risk management:
ITSM and ITIL practices incorporate best practices for risk management. Organisations and public authorities can use these methods to identify and minimise potential risks associated with the use of AI. Those who need to meet further compliance requirements in this area can extend this risk management to include information security by applying additional standards and frameworks, such as the BSI Standard 200-3 ‘Risk Analysis Based on IT-Grundschutz’.
Security standards:
ITIL practices place great emphasis on the security of IT services. By implementing these security standards through the ITIL practice ‘Information Security Management’, organisations can ensure that their AI systems comply with the requirements of the EU AI Act. Here, further standards, such as an effective ISMS based on BSI Basic Protection or ISO/IEC 27001, can significantly broaden the scope of application.
Strategy Management:
The ITIL Practice of Strategy Management describes how strategies are designed within ITSM and implemented to a high ethical standard. This enables a well-developed strategy and objectives for AI deployment to be defined, and the ‘Job to be Done’ approach to be optimally implemented and planned. The use of AI is structured and goal-oriented.
Service Level Management:
Service Level Management ensures that agreed service levels are maintained and that services meet customer expectations. In the context of the EU AI Act, it is important for organisations to establish clear Service Level Agreements (SLAs) for their AI systems, which ensure compliance with regulatory requirements and the implementation of the strategy regarding AI applications. This includes defining key performance indicators, monitoring service quality and regularly reviewing the SLAs.
Service Design Management:
The ITIL practice of service design ensures that new or modified services meet the requirements of the organisation and its customers. By incorporating security and compliance requirements as early as the design phase, organisations can ensure that their AI systems meet the strict requirements of the EU AI Act. This includes defining security controls, data protection measures and ethical standards.
Incident Management:
Incident Management focuses on the rapid restoration of normal service operations following an incident. In the context of the EU AI Act, it is important that organisations have processes in place to quickly detect and resolve incidents relating to AI systems. This includes identifying security incidents, assessing their impact on compliance and implementing measures to prevent future incidents.
Problem Management:
Problem management aims to identify the root causes of incidents and find permanent solutions. By implementing an effective problem management process, organisations can ensure that recurring issues relating to AI systems are resolved, thereby ensuring compliance with the EU AI Act. This involves analysing incidents, identifying trends and implementing corrective measures.
Change Management:
Change management is an essential component of ITSM and ensures that all changes to IT services are carried out in a controlled and coordinated manner. A robust change management process ensures that changes to AI systems are carefully reviewed and approved to minimise compliance risks. This involves assessing the impact of changes on compliance with the EU AI Act and documenting all changes.
Continual Improvement:
ITSM and ITIL practices promote a culture of continuous improvement. This enables organisations to regularly review and adapt their IT processes to ensure they always meet the latest compliance requirements. This ongoing optimisation also promotes value creation and, where necessary, aligns it with the changing market.
Knowledge Management:
The ITIL practice of knowledge management ensures that knowledge is effectively captured, stored and utilised within the organisation. In the context of the EU AI Act, it is important that organisations have access to up-to-date and accurate information on compliance requirements and best practices. This includes creating and maintaining knowledge databases, providing training and fostering a culture of knowledge sharing.
Measurement and Reporting:
The ITIL®4 ‘Measurement and Reporting’ practice ensures rigorous, consistent measurement of key performance indicators across the entire organisation. This prevents inconsistencies and the resulting queries during compliance audits. With an effective monitoring system in place, it is possible not only to monitor the risks associated with AI operations, but also to identify malfunctions and deviations from the IT strategy and legal requirements at an early stage.
3. Practical Implementation
To use ITSM and ITIL practices effectively to comply with the EU AI Act, organisations should take the following steps:
Training and awareness-raising:
Staff should receive regular training to ensure they understand and can implement the requirements of the EU AI Act. The ITIL®4 practice ‘Workforce and Talent Management’, for example, supports the implementation of necessary training measures. Knowledge is made available in a transparent and traceable manner to all relevant parties through an established knowledge management system.
Implementation of ITIL practices:
Both private sector organisations and public authorities should integrate ITIL practices into their IT processes to ensure a structured and proven approach. A structured approach makes it possible to deliver measurable value and map out use cases.
Monitoring and reporting:
It is important to continuously monitor compliance with the EU AI Act and to produce regular reports to ensure that all requirements are met. Various practices, with their key performance indicators, can support this, in particular the “Measurement and Reporting” practice. In this context, compliance and regular review in the form of service reviews are a key part of the ongoing assessment of the extent to which strategy, compliance with the EU AI Act and customer-specific implementation align or need to be adjusted. Relationships with suppliers and partners must also be taken into account here.
Conclusion
Compliance with the EU AI Act is of crucial importance for organisations that use AI. ITSM and ITIL practices offer a proven methodology for ensuring that all compliance requirements are met. By implementing these methods, organisations and public authorities can optimise their IT processes and ensure that their AI systems comply with the strict requirements of the EU AI Act and operate in line with strategic objectives.
You can find out more about the EU AI Act here.