Whether it’s lending, applicant management, or claims processing: More and more business processes today incorporate artificial intelligence—for preliminary screening, categorization, or text generation. With the EU AI Act, the European Union’s regulation on artificial intelligence, this use is now subject to a binding legal framework.
On June 29, 2026, the Council of the European Union gave its final approval to the so-called AI Omnibus. The amending regulation entered into force on July 27, 2026, and, among other things, deferred the application of certain requirements for high-risk AI systems.
For government agencies, banks, insurance companies, and other regulated organizations, this raises a key question: How can the use of AI in business processes be structured in such a way that it is traceable, documented, and verifiable in the event of an incident? This is exactly where the BPM engine CIB seven comes into play.
Focus on Process Automation
In practice, AI is rarely used in isolation but is instead embedded in a business process: A model evaluates an application, a case worker reviews it and makes a decision, and a system documents the process. The following information, in particular, may be relevant for maintaining a reliable audit trail:
- Which model was used?
- With what prompt?
- Who reviewed and approved the result?
For organizations that integrate AI into their operations via a business process management platform, this means that traceability must be embedded in the process itself, rather than reconstructed after the fact.
CIB seven: Logging AI Interactions in the Process
To meet these requirements, CIB seven offers the AI Agent Connector. It integrates OpenAI-compatible language model interfaces via a library and logs which model was used, with which prompt, with which model parameters, as well as which tools were incorporated via the Model Context Protocol (MCP) or which knowledge sources were included via Retrieval-Augmented Generation (RAG). By default, all calls are recorded in the audit trail of the respective process.
Traceability is not achieved solely through AI logging
However, logging AI interactions is only one aspect of traceability. The process context is just as important: Where does a document come from? Who processed which step? Which transaction ID is associated with the workflow?
Such information can be mapped in a low-code process platform such as CIB flow using process variables and unique operation IDs. In this way, CIB flow complements the CIB seven perspective with an operational process view, while CIB seven makes the AI interactions themselves auditable.
Complete prompts and responses may contain personal or confidential information. CIB seven offers content editing services for this purpose. However, retention periods, access permissions, and data protection policies must still be defined at the organizational level.
It is crucial that companies actively incorporate this information into their planning for AI implementation in the process.
A real-world example
A typical use case is processing incoming service requests. An AI model categorizes the request, compares it with existing knowledge sources, and generates a draft response. An employee reviews the suggestion, adds to it if necessary, and then approves the response.
If such a workflow is orchestrated via CIB seven, it is possible to track which model was used, which request and which information were processed, which tools or knowledge sources were involved, and who reviewed and approved the draft response.
In this way, AI interaction, process context, and human decision-making are integrated into a seamless workflow. Logging helps companies ensure transparency in their use of AI and meet internal documentation requirements.
Platform and Process Design: Shared Responsibility
Important for context: A platform can establish the technical prerequisites for traceability—whether a specific process is actually EU AI Act-compliant also depends on what data is collected, how inputs and outputs are documented, and how approvals are organized. This means that AI compliance is not an after-the-fact formality, but rather an integral part of process design—the responsibility for this lies with the organization designing the process, not solely with the software being used. This overview does not replace individual legal advice; when it comes to concrete implementation, it is recommended to consult with legal counsel and your own compliance officers.
Is your company prepared for the EU AI Act?
The EU AI Act defers some of its requirements to the future, but makes it clear in which direction regulated processes are heading: greater transparency regarding AI use, greater traceability, and more documentation. With the AI Agent Connector and process-embedded logging, CIB seven is already laying a solid foundation for this today—and will continue to evolve consistently in this direction.
Learn more about CIB BPM solutions and talk to our digital transformation experts if you want to prepare your processes for the EU AI Act.