Blog

EU AI Act and SAP: Turning a Regulatory Obligation into a Governance Advantage

  • The EU AI Act makes AI governance a business priority rather than simply a compliance exercise, giving SAP organizations an opportunity to strengthen existing security, GRC, data governance, risk, and audit practices.

  • AI risk depends on how a system is used rather than on the underlying technology or model, so the same AI capability can face very different requirements depending on its purpose, data, users, and level of autonomy.

  • Legal high-risk classification and business criticality are different, meaning an AI system can have major operational consequences without being legally high-risk under the AI Act.

  • Governance should evolve as AI systems change, with controls such as human oversight, access restrictions, testing, logging, approval limits, model-version tracking, and reassessment as autonomy increases.

  • Most SAP organizations can build on capabilities they already have across security, GRC, data, procurement, and audit, with the key challenge being clear ownership and accountability across teams.

  • Organizations should treat AI governance as an ongoing process rather than a one-off compliance project, maintaining a clear view of where AI is used, what it influences, who is accountable, and how it is controlled.  

AI
Rene Nakache
Written By Rene Nakache
written

3 Sep, 2026 — 12 min read

Table of contents

EU AI Act and SAP: Turning a Regulatory Obligation into a Governance Advantage
18:08

Artificial intelligence is playing an increasingly prominent role within SAP environments. As organizations adopt these technologies across finance, procurement, supply chain, production, HR, and other core business processes, AI is moving beyond supporting users towards increasingly influencing decisions and, in some cases, taking actions directly within business systems.   

This shift reflects SAP’s vision of the Autonomous Enterprise, in which AI assistants and AI agents can increasingly support and execute business processes alongside human users. As AI takes on a more active role in enterprise operations, it becomes increasingly important for organizations to understand where AI is being used, what it can influence, what data it can access, and how its outputs and actions are governed and controlled.  

The EU AI Act adds an important regulatory dimension to this evolving landscape. The Act takes a risk-based approach, meaning that the obligations associated with an AI system depend on what it is designed to do, what it is used for, and the context in which it operates. The same underlying technology can therefore be subject to very different requirements depending on the business process it supports, the people affected, the decisions it influences, and the degree of autonomy it has.   

For organizations running SAP, this creates an opportunity to build on existing security, GRC, risk, data governance, and audit capabilities and use the AI Act as a catalyst for a more structured approach to AI governance across the business. This article explores how the EU AI Act applies to AI use cases in SAP environments and how organizations can translate its requirements into a practical framework for AI governance, risk management, and accountability.   

The EU AI Act Changes How Organizations Need to Govern AI in SAP  

The AI Act entered into force on August 1, 2024, and is being implemented in stages, with several requirements already applicable. For organizations running SAP, understanding the regulatory implications requires more than simply identifying which AI technologies are being deployed. Companies need to establish where AI is being used, what data and business processes it can influence, their role within the AI value chain, how AI outputs may affect business decisions, and who is ultimately accountable for those outcomes.  

Once AI is embedded within an SAP environment, the discussion quickly moves from regulatory requirements to practical operational and technological considerations. Unlike traditional enterprise software, which is generally expected to produce consistent results from the same inputs, AI systems, particularly generative AI models, can produce different outputs depending on factors such as the model version, configuration, context, and sampling process. This makes effective testing, logging, traceability, and reproducibility particularly important when AI is used to support or influence business processes and decisions. Organizations also need to consider what happens when an AI output is incorrect, including whether the system is limited to providing a recommendation or can take action directly.  
 
Clear accountability is equally important, particularly where multiple parties are involved. Organizations need to understand who provides the AI technology, who operates it, who owns and controls the underlying data, how user data is handled, what role each party has under the AI Act, and how much autonomy the system has to influence decisions or perform actions.  
 
Ultimately, the obligations under the AI Act depend not only on the technology being used but also on its intended purpose, the way it is deployed, and the context in which it operates. Organizations therefore need to assess each AI use case individually, establish how it is classified under the Act, and determine which requirements apply so that AI can be deployed within SAP environments in a way that is both legally compliant and appropriately governed.

Understanding the EU AI Act in Practice  

The EU AI Act takes a risk-based approach, with its legal categories designed to address potential risks to people’s health, safety, and fundamental rights, while also safeguarding democracy and the rule of law. The specific classification of an AI system depends on its intended purpose and the context in which it is used. An AI system is not classified simply by the underlying model or software product; rather, its classification depends on how and where it is deployed.

This distinction is particularly important when assessing AI used within business-critical SAP processes. Herein, an AI system may be operationally critical because it can influence inventory, production, payments, supplier relationships, or safety without necessarily being classified as high-risk under the AI Act. Conversely, an AI system used to screen job applicants may fall within a high-risk category because its intended purpose can affect a person's access to employment.  
 
For organizations using SAP, legal risk classification and business criticality should therefore be assessed separately. Considering both dimensions provides a more complete understanding of risk and helps organizations determine the appropriate governance, controls, and oversight for each AI use case. Here are some key examples of classification under the AI act.  

Minimal or no Risk

Most AI systems do not fall into a prohibited, high-risk, or specific transparency category, and many common business applications will therefore have relatively limited obligations under the AI Act. This can include applications such as report summarization, translation, document search, and meeting-note generation. For example, within SAP, an AI assistant might summarize delayed orders or stock variances for a user. Applications of this nature would generally be considered low-risk use cases under the AI Act, although organizations should still assess the specific implementation and context in which the AI is being used.

Specific Transparency Obligations 

Certain interactive and generative AI systems are subject to specific transparency 
requirements under the AI Act. Depending on the use case, users may need to be informed that they are interacting with an AI system, while AI-generated or manipulated content may need to be identified or labeled. Within SAP, an AI assistant that answers questions about orders, invoices, or contracts could potentially fall within these requirements, depending on how it operates and what it produces.   

High-Risk AI Under the AI Act

"High-risk" is a specific legal classification under the AI Act and should not be confused with how important or business-critical an AI system is. Broadly, high-risk classification can arise through two routes. The first concerns AI systems that are either safety components of certain regulated products or are themselves regulated products subject to specific conformity assessment requirements. For example, an AI system used as a safety component in a medical device or industrial machinery could fall into this category. The second concerns AI systems used for specific purposes, including certain applications in employment, education, critical infrastructure such as energy, water and transport systems, essential services, migration, law enforcement, and the administration of justice.

Within an SAP environment, an AI system connected to SAP SuccessFactors that ranks job candidates or evaluates employees could require particular attention because it may affect access to employment. Similarly, an SAP-connected AI system could potentially form part of a regulated product or safety-related system where the relevant legal conditions are met. Where an AI system is classified as high-risk, the applicable requirements can include risk management, data governance, technical documentation, logging, human oversight, accuracy, robustness, and cybersecurity. Organizations should therefore assess classification on a case-by-case basis, rather than assuming that a particular SAP product, AI feature, or underlying model automatically determines its legal status.  

General-Purpose AI

The AI Act also establishes obligations relating to providers of general-purpose AI models. For organizations using SAP, the practical challenge is understanding where these models sit within the technology stack and which responsibilities rest with the model provider, SAP, another technology supplier, or the organization itself. This makes it important to understand the wider AI value chain, including how models support AI agents and connect to enterprise applications, data, and business processes. 
 
SAP’s AI Agent Hub provides an example of how this broader landscape can be brought into view. Its vendor-agnostic approach supports the discovery, inventory, governance, and evaluation of AI agents, LLMs, and MCP servers across SAP and third-party environments. This can help organizations maintain visibility of the AI assets connected to their business processes and clarify ownership, oversight, and accountability as AI capabilities evolve. 

Prohibited Practices

At the most restrictive end of the framework are prohibited AI practices, which cover defined uses such as certain forms of social scoring, manipulative or deceptive techniques, exploitation of vulnerabilities, certain forms of biometric categorization, and certain uses of emotion recognition.  

These prohibitions are deliberately specific and should not be interpreted as a general ban on particular technologies or outcomes. For example, the prohibition on manipulative or deceptive techniques applies to defined practices that materially distort behavior in circumstances specified by the Act and involve significant harm. Similarly, workplace emotion recognition is subject to specific rules and exceptions.  
 
Although these use cases may be less common within core SAP processes, connected applications still require consideration, particularly where third-party HR, employee monitoring, surveillance, or profiling tools use SAP data. The practical lesson for SAP organizations is therefore to challenge potentially sensitive AI use cases early in the design, architecture, and procurement process, rather than waiting until after deployment to consider their regulatory implications.  

As AI becomes increasingly embedded across SAP and connected business processes, organizations need a governance approach that can address not only regulatory classification but also how AI is deployed, controlled, monitored, and used within critical operations.   

Why AI Governance Matters in the SAP Landscape

In many organizations, SAP sits at the center of finance, procurement, supply chain, production, maintenance, logistics, and workforce processes. SAP’s vision of the Autonomous Enterprise is moving AI closer to these operational workflows, with the SAP Autonomous Suite designed to deploy more than 50 domain-specific Joule Assistants that orchestrate a subset of more than 200 specialized AI agents across finance, supply chain, procurement, human capital management, and customer experience.  
 
For example, SAP’s Autonomous Close Assistant is designed to automate journal entries, reconciliation, and error resolution across the financial close process, potentially reducing a process that takes weeks to days. As AI moves from assisting users towards orchestrating and executing end-to-end processes, governance becomes increasingly important: organizations need to understand what data agents can access, what decisions they can influence, what actions they can take, and what controls apply when their level of autonomy increases. 

The AI Act offers an opportunity for organizations to build a clearer picture of how AI is already being used across teams. A structured review can identify production systems, pilots, third-party tools, and shadow AI experiments, while also showing which teams are using AI, what data those tools can access, and which decisions rely on their outputs. It can highlight where ownership is unclear, where suppliers play an important role, and where existing controls may not match the level of operational exposure.  
 
Organizations need a living, owned, and actionable baseline that can be maintained as AI use changes. This baseline can sit within existing capabilities such as SAP Signavio, a GRC platform, or, where justified, a specialist AI governance solution. The important point is that AI governance becomes part of established processes for risk, security, data, procurement, audit, and change management rather than creating an isolated compliance exercise. Organizations need a flexible, owned, and actionable baseline that can evolve as AI use, capabilities, and associated risks change. This baseline can sit within existing capabilities such as SAP Signavio, a GRC platform, or, where justified, a specialist AI governance solution. The important point is that AI governance becomes part of established processes for risk, security, data, procurement, audit, and change management, rather than creating an isolated compliance exercise.

A Practical Approach to AI Governance in SAP

A practical approach to AI governance in SAP should therefore begin with discovery. SAP environments are not necessarily closed AI ecosystems. Organizations may connect SAP processes and data with third-party AI models, agents, applications, and integration services, creating a broader landscape that extends beyond SAP’s own AI capabilities. SAP AI Agent Hub reflects this reality by providing a vendor-agnostic view of AI agents, LLMs, and MCP servers across SAP and third-party environments. This makes AI discovery and governance important across the wider technology environment: organizations need to understand which AI components connect to SAP, what data and processes they can access, and who is responsible for their outputs and actions. 

For each identified use case, organizations should understand what the system does, what data it uses, which business process it supports, and whether it informs, recommends, decides, or executes an action. Each use case should then be assessed from two perspectives: its legal classification under the AI Act and its operational, financial, security, data, and fundamental-rights impact. This helps distinguish legal classification from business criticality while establishing are ownership across business teams, IT, security, data, procurement, and suppliers.  
 
Governance should then establish controls appropriate to each use case and ensure they remain effective as the technology evolves. These may include access restrictions, human oversight, testing, logging, approval limits, model-version tracking, and reassessment when significant changes occur. For example, an AI agent used in procurement might initially recommend a supplier or purchase order for human approval. If the same agent is later permitted to create or approve purchase orders automatically, its governance requirements should change accordingly. Access rights, approval thresholds, human oversight, testing, logging, and monitoring would need to reflect the increased decision authority and potential impact of an incorrect action. This is particularly important where model behavior can change without changes to the surrounding SAP process, or where an AI system moves from providing recommendations to taking actions directly.  
 
The SAP AI Agent Hub supports this approach by giving organizations a clearer view of the AI agents operating across their environment. Importantly, it also helps organizations assess and manage the risks associated with AI agents by providing greater visibility into their ownership, capabilities, data access, decision authority, and behavior. This enables organizations to identify potentially higher-risk agents and apply appropriate controls. It also makes it easier to monitor agents throughout their lifecycle and maintain evidence of how risks are being managed.  
 
Most SAP organizations already have many of the capabilities needed for effective AI governance. The challenge is connecting these responsibilities around each AI use case, particularly where the model, data, business process, and decision are owned by different teams or third-party providers. Effective AI governance depends on bringing these existing capabilities together around a clear view of the AI use case and establishing accountability throughout its lifecycle.  

Summary

The EU AI Act gives SAP organizations a clear reason to understand how AI is already being used across the business and where it has the greatest influence. The regulatory framework is being introduced in stages, with requirements already applying to areas such as prohibited practices, governance, general-purpose AI, and transparency. Organizations therefore need to keep both their AI inventory and their understanding of the regulatory timetable under review.  

For SAP customers, the most useful approach is to connect legal classification with business criticality, process context, security, data governance, and technical assurance. A system does not need to be legally high-risk to deserve strong controls, and a legal classification should never be inferred simply from how important a system is to the business. Organizations that can explain where AI is used, what it influences, who is accountable, and how it is controlled will be better placed to meet regulatory requirements while continuing to adopt AI with confidence.  
 
Turnkey Consulting can help you assess your current AI use cases, distinguish regulatory requirements from business risk, identify governance gaps, and establish a practical roadmap for next steps. Book an AI governance consultation to start building a clear, actionable view of your AI landscape.  

 

FAQs

Does every AI system used with SAP fall under the AI Act's high-risk rules?

No. High-risk is a specific legal classification under the AI Act and depends on the intended purpose and context of use. An AI system can also be highly important to the business without being legally classified as high-risk. For example, an AI tool that summarizes documents has a different classification from one that ranks job candidates or performs a function within a regulated, safety-critical product.  

Why does the EU AI Act matter for SAP in particular?

SAP underpins many of the processes businesses rely on every day, from finance and procurement to supply chain, production, maintenance, and HR. As AI becomes more embedded in these processes, organizations need to understand where it is being used, what it is designed to do, and whether specific requirements under the EU AI Act apply. An AI system’s business importance or potential impact does not, on its own, determine its classification under the Act. However, understanding how AI is used within SAP processes is essential to applying the right governance and controls.

Where should organizations start with SAP and the AI Act?

Organizations should start by finding out where AI is already being used and how. This includes SAP products and extensions, AI capabilities provided through the SAP ecosystem, third-party tools, and AI experiments taking place within individual teams. Without a reliable inventory, it is difficult to determine which use cases are legally regulated, operationally critical, or subject to particular governance requirements.  

Related posts

April 26, 2026

AI in SAP: Balancing Opportunity, Risk, and Control

March 13, 2026

Missed TAC CCR 2026? Here are the 3 big takeaways