Use case · Customer operations
Keep customer-support AI inside a clear and reviewable operating boundary.
A support assistant can draft text, answer customers, retrieve account information or take actions. Those are materially different uses. EU AI Fit helps teams record what the system may do, how people are informed, when a human takes over and what evidence shows the controls operate.
Product demonstration · 2 minutes 14 seconds
Operational AI assurance
Connect risks, controls, indicators, incidents, FRIA readiness, recovery exercises and recurring managed reviews using hypothetical data. All organisations, people and systems shown were created for demonstration, and no client data appears.
Read the video transcript
Putting an AI system into use is where operational assurance begins. EU AI Fit brings together current risks, overdue reviews, open incidents and actions requiring an owner. Each risk records cause, possible harm, controls, indicators and escalation thresholds.
Incident records preserve facts and the rationale for internal or regulatory reporting decisions without declaring an event reportable automatically. Incident and recovery exercises preserve roles, communications, recovery objectives, lessons and corrective actions.
FRIA readiness structures Article 27 fact gathering, and the managed compliance desk brings inventory, classification, evidence, suppliers, incidents, training and regulatory updates into a recurring review. The result is an operating record, not a certificate.
Why this needs control
A helpful chatbot can become an uncontrolled decision or action channel.
Risk changes when a system moves from drafting a reply to giving authoritative information, interpreting vulnerability, making an eligibility judgement or changing a customer account. The organisation needs to govern those changes as new purposes, not ordinary feature releases.
Transparency is also contextual. The team must establish whether and when people should know they are interacting with AI, how escalation works and what evidence proves the disclosure and oversight controls are present.
In this scenario
Harbour Support Copilot
A subscription business wants one assistant to draft agent replies and answer routine customer questions directly.
- The internal drafting use is reviewed separately from the public chatbot.
- The public version may retrieve account facts but cannot change billing or cancellation status.
- Approved disclosure wording and human hand-off rules are not yet implemented.
- The model provider can change the underlying version with notice.
The organisation separates the two use cases, records the public interaction trigger, assigns disclosure and hand-off evidence, and creates a reassessment trigger for model or action-scope change.
Every organisation, person and system in this scenario is hypothetical and contains no client data.
Practical workflow
From proposed use to a maintained decision.
- 01
Separate each purpose
Record drafting, direct interaction, retrieval, recommendation and account action as distinct uses where their facts or controls differ.
- 02
Review transparency
Identify direct-interaction and synthetic-content triggers, approved wording, timing, accessibility and implementation evidence.
- 03
Define human authority
Set the hand-off conditions, prohibited actions, review sampling, override route and response to vulnerable or disputed cases.
- 04
Monitor the live boundary
Track output failures, complaints, security events, model changes and attempted use outside the approved purpose.
What the record should retain
Evidence follows the use case.
- Purpose-specific inventory records
- Direct-interaction disclosure decision
- Approved wording and interface evidence
- Human hand-off and override instructions
- Supplier model and change information
- Quality indicators, complaints, incidents and reassessment
Continue the review
Read the connected guidance.
Next step
Start with the system and use you are actually proposing.
Run the initial exposure check, then retain the deeper assessment, responsibility and evidence work inside a controlled workspace.
Run the free check