05.06.2025
Blog
Regulatory
Think ahead

Compliance meets sustainability: ITSM & ITIL in the age of the EU AI Act

Compliance with the EU AI Act is of crucial importance for organisations that use artificial intelligence (AI). IT service management (ITSM) and ITIL practices offer a structured and proven approach to ensuring that compliance requirements are met. This article demonstrates how ITSM and ITIL practices help businesses and public authorities to comply with the EU AI Act whilst creating sustainable value.

Frank Eggert
Principal Consultant

1. Introduction to the EU AI Act

The EU AI Act is legislation designed to regulate the use of AI within the European Union. It sets out strict requirements regarding transparency, security and ethical standards that organisations must meet in order to use AI systems lawfully.

2. The Role of ITSM and ITIL Practices

ITSM and ITIL practices provide a structured approach to the management of IT services. These methods help organisations optimise their IT processes and ensure that all compliance requirements are met. Here are some key areas in which ITSM and ITIL practices support compliance with the EU AI Act: 

Transparency and documentation:

 ITIL practices promote comprehensive documentation of all IT processes and services. This helps to ensure the necessary transparency and provide all relevant information required for compliance with the EU AI Act. 

Risk management:

ITSM and ITIL practices incorporate best practices for risk management. Organisations and public authorities can use these methods to identify and minimise potential risks associated with the use of AI. Those who need to meet further compliance requirements in this area can extend this risk management to include information security by applying additional standards and frameworks, such as the BSI Standard 200-3 ‘Risk Analysis Based on IT-Grundschutz’.  

Security standards:

ITIL practices place great emphasis on the security of IT services. By implementing these security standards through the ITIL practice ‘Information Security Management’, organisations can ensure that their AI systems comply with the requirements of the EU AI Act.  Here, further standards, such as an effective ISMS based on BSI Basic Protection or ISO/IEC 27001, can significantly broaden the scope of application. 

Strategy Management:

The ITIL Practice of Strategy Management describes how strategies are designed within ITSM and implemented to a high ethical standard. This enables a well-developed strategy and objectives for AI deployment to be defined, and the ‘Job to be Done’ approach to be optimally implemented and planned. The use of AI is structured and goal-oriented. 

Service Level Management:

Service Level Management ensures that agreed service levels are maintained and that services meet customer expectations. In the context of the EU AI Act, it is important for organisations to establish clear Service Level Agreements (SLAs) for their AI systems, which ensure compliance with regulatory requirements and the implementation of the strategy regarding AI applications. This includes defining key performance indicators, monitoring service quality and regularly reviewing the SLAs. 

Service Design Management:

The ITIL practice of service design ensures that new or modified services meet the requirements of the organisation and its customers. By incorporating security and compliance requirements as early as the design phase, organisations can ensure that their AI systems meet the strict requirements of the EU AI Act. This includes defining security controls, data protection measures and ethical standards. 

Incident Management:

Incident Management focuses on the rapid restoration of normal service operations following an incident. In the context of the EU AI Act, it is important that organisations have processes in place to quickly detect and resolve incidents relating to AI systems. This includes identifying security incidents, assessing their impact on compliance and implementing measures to prevent future incidents. 

Problem Management:

Problem management aims to identify the root causes of incidents and find permanent solutions. By implementing an effective problem management process, organisations can ensure that recurring issues relating to AI systems are resolved, thereby ensuring compliance with the EU AI Act. This involves analysing incidents, identifying trends and implementing corrective measures. 

Change Management:

Change management is an essential component of ITSM and ensures that all changes to IT services are carried out in a controlled and coordinated manner. A robust change management process ensures that changes to AI systems are carefully reviewed and approved to minimise compliance risks. This involves assessing the impact of changes on compliance with the EU AI Act and documenting all changes. 

Continual Improvement:

ITSM and ITIL practices promote a culture of continuous improvement. This enables organisations to regularly review and adapt their IT processes to ensure they always meet the latest compliance requirements. This ongoing optimisation also promotes value creation and, where necessary, aligns it with the changing market. 

Knowledge Management:

The ITIL practice of knowledge management ensures that knowledge is effectively captured, stored and utilised within the organisation. In the context of the EU AI Act, it is important that organisations have access to up-to-date and accurate information on compliance requirements and best practices. This includes creating and maintaining knowledge databases, providing training and fostering a culture of knowledge sharing. 

Measurement and Reporting:

The ITIL®4 ‘Measurement and Reporting’ practice ensures rigorous, consistent measurement of key performance indicators across the entire organisation. This prevents inconsistencies and the resulting queries during compliance audits. With an effective monitoring system in place, it is possible not only to monitor the risks associated with AI operations, but also to identify malfunctions and deviations from the IT strategy and legal requirements at an early stage.

3. Practical Implementation

To use ITSM and ITIL practices effectively to comply with the EU AI Act, organisations should take the following steps: 

Training and awareness-raising:

Staff should receive regular training to ensure they understand and can implement the requirements of the EU AI Act. The ITIL®4 practice ‘Workforce and Talent Management’, for example, supports the implementation of necessary training measures. Knowledge is made available in a transparent and traceable manner to all relevant parties through an established knowledge management system. 

Implementation of ITIL practices:

Both private sector organisations and public authorities should integrate ITIL practices into their IT processes to ensure a structured and proven approach. A structured approach makes it possible to deliver measurable value and map out use cases. 

Monitoring and reporting:

 It is important to continuously monitor compliance with the EU AI Act and to produce regular reports to ensure that all requirements are met. Various practices, with their key performance indicators, can support this, in particular the “Measurement and Reporting” practice. In this context, compliance and regular review in the form of service reviews are a key part of the ongoing assessment of the extent to which strategy, compliance with the EU AI Act and customer-specific implementation align or need to be adjusted. Relationships with suppliers and partners must also be taken into account here. 

Conclusion 

Compliance with the EU AI Act is of crucial importance for organisations that use AI. ITSM and ITIL practices offer a proven methodology for ensuring that all compliance requirements are met. By implementing these methods, organisations and public authorities can optimise their IT processes and ensure that their AI systems comply with the strict requirements of the EU AI Act and operate in line with strategic objectives. 

 

You can find out more about the EU AI Act here. 

Frank Eggert
Principal Consultant

Frank Eggert ist Principal Consultant, syst. Coach und ITIL Trainer bei Materna. Als akkreditierter ITIL®4 Ambassador beherrscht er das Service Management-Umfeld und berät Kunden dabei, ein konformes Service Management-System zu etablieren.

Related articles

Event
Frankfurt am Main
18.11.2026
BMC Helix Roadshow 2026

Meet Materna at the BMC Helix Roadshow 2026 on 18 November in Frankfurt and discover how modern service management, Agentic AI and compliance requirements work together successfully. Look forward to exclusive insights into the BMC Helix roadmap, the…

Read more
Event
Dortmund
05.11.2026
XCS Day (Xchange in Cyber Security)

At XCS Day, experts from the business and public sectors will once again come together to discuss current challenges and strategies relating to cyber security and regulation. Find out how organisations are strengthening their resilience to cyber…

Read more
Event
Dortmund
03.11.2026
FMS Information Day

On 3 November 2026, we will update you on the latest developments relating to the Federal Government’s FMS and encourage mutual exchange. The keen interest you show in every issue demonstrates that the FMS is, and will remain, a key element of…

Read more
Event
Wien
13.10.2026
Agentic AI Roundtable in Vienna

How does Agentic AI deliver real added value for IT and service organisations? At the Agentic AI Roundtable in Vienna, Materna, BMC Helix and other experts will discuss specific use cases, current challenges and next steps for businesses. Look…

Read more
Event
Berlin
13.10.2026 - 15.10.2026
Smart Country Convention (SCCON)

Come and meet us in Hall 27 at Stand 206 at the leading event for the digital state and public services. SCCON is a must-attend event for all stakeholders actively driving and shaping digital transformation. At our stand, you’ll find a use case…

Read more
Event
Amsterdam
06.10.2026 - 08.10.2026
Atlassian Team ’26 Europe

From 6 to 8 October 2026, Atlassian will be bringing the community together for ‘Team ’26 Europe’ in Amsterdam. Look forward to hands-on sessions covering AI, new products and features, live demos and certification opportunities. You’ll also have the…

Read more
Event
Berlin
01.10.2026
Open Insurance Dialog 4.0 (#OID4.0)

Open Insurance Dialog 4.0: FiDA, Identity and New Opportunities for Insurers

The insurance industry is facing a profound transformation: FiDA (Financial Data Access) and Open Insurance are creating new opportunities for data-driven services,…

Read more
Event
Online
30.09.2026
Webcast: ‘Understanding the mainframe, accelerating migration: How banks and insurers are harnessing hidden knowledge’

Mainframe and legacy systems contain decades of business logic – often inadequately documented and difficult to access. From 10.00 to 11.30, Materna and Nomain will demonstrate how AI-powered analyses can make business logic, dependencies and…

Read more
Event
Düsseldorf
30.09.2026
27th NRW ÖV Symposium

Artificial intelligence, digital sovereignty, the cloud, the data economy and cyber security form the framework for the digital transformation of public administration in North Rhine-Westphalia. This popular platform for information and dialogue on…

Read more
Event
Public Sector
Online
24.09.2026
Webcast: ‘From a jungle of registers to a digital ecosystem.’

How register modernisation, the ‘once-only’ principle and NOOTS are bringing about lasting change in public administration. Find out what challenges public authorities face, which strategies are proving effective, and how a future-proof register…

Read more