AI literacy and internal AI policy

What the AI Act asks about training, transparency notices and internal AI use, and what the GDPR adds, with the articles.

Do I have to train my employees in AI?

You have to take measures, but not guarantee a level: since 2 February 2025 Article 4 of the AI Act has required providers and deployers to act on their staff's AI literacy. Since 27 July 2026, in the wording given by Regulation (EU) 2026/1744, the duty is to "take measures to support" that literacy, without guaranteeing any specific level of any individual.

The original wording asked for measures to ensure, "to their best extent", a sufficient level of AI literacy. The Digital Omnibus on AI (Article 1, point 5, of Regulation 2026/1744) replaced Article 4: the measures take into account people's technical knowledge, experience, education and training, the context the systems are used in and the persons they are used on, and the Commission and Member States must support SMEs in particular, with practical examples published by the Commission. The Omnibus entered into force on 27 July 2026, the third day after its publication on 24 July, with no separate date for this article. According to the Commission no certificate is needed: an internal record of trainings and other initiatives is enough. If you use high-risk AI, Article 26(2) still requires the people overseeing it to have the necessary competence, training and authority.

Reviewed: Read the full guide →

Do I need an AI use policy?

Not literally: if you use systems that are not high-risk, the AI Act does not require a document called an "AI use policy". It does require AI-literacy measures (Article 4), and the GDPR requires you to be able to demonstrate that you process personal data properly (Articles 5(2) and 24); a short policy is the practical way to evidence both.

GDPR Article 24(2) provides that, where proportionate, the controller's measures include "appropriate data protection policies", and Article 32(4) requires it to ensure that anyone acting under its authority processes personal data only on its instructions. For Article 4, the Commission states that no certificate or specific governance structure is required (no AI officer, no board), and that an internal record of trainings and initiatives is enough. A short policy usually covers which tools are approved, which data is never entered, who reviews AI output before it is used externally, and how staff are trained and recorded. If you use Annex III high-risk AI, Article 26 adds its own obligations, applicable from 2 December 2027.

Reviewed: Read the full guide →

Do I have to tell my customers they are talking to an AI?

If it is a chatbot, usually yes: since 2 August 2026 Article 50(1) requires that people interacting with an AI system are informed of it, unless this is obvious. Formally it is the provider's duty, but if you build your own assistant on a third-party model and put it into service under your name, the provider may be you (Article 3(3)).

As a deployer, Article 50(4) requires you to disclose that content is artificial in two cases: deep fakes (image, audio or video that appears authentic) and AI-generated or manipulated text you publish to inform the public on matters of public interest, unless it has undergone human review or editorial control and someone holds editorial responsibility. The notice must be clear and distinguishable, at the latest at the first interaction or exposure (Article 50(5)). Article 25, which turns into a provider anyone who puts their name on a system or modifies it, only concerns high-risk systems. Article 50 applies from 2 August 2026; Regulation (EU) 2026/1744 only gives until 2 December 2026 for the machine-readable marking of Article 50(2) in generative systems placed on the market before 2 August 2026, and does not change paragraphs 1 and 4.

Reviewed: Read the full guide →

What if an employee uses ChatGPT on their own ("shadow AI")?

The most immediate risk is data protection: if they paste customers' or employees' personal data into a personal account, that processing escapes your instructions, and as controller you are expected to have taken steps to prevent it (GDPR Articles 29 and 32(4)). In addition, the AI Act defines a deployer by use "under its authority" and only excludes personal non-professional activity, so use for work tasks is unlikely to fall outside your Article 4 duty.

GDPR Article 29 prevents anyone acting under the controller's authority from processing personal data except on its instructions, and Article 32(4) requires the controller to take steps to ensure this. If a provider processes data on your company's behalf, Article 28 requires a processing contract, which an account the employee opened personally does not create between your company and that provider. The AI Act does not expressly address unauthorised AI, but the Commission confirms that a company whose employees use ChatGPT to, for example, write advertising copy or translate text is subject to Article 4 and should inform them of risks such as hallucination. In practice: inventory what is being used, offer an approved alternative (local, or under a processing contract), set which data is never entered, and train your staff.

Reviewed: Read the full guide →

Who should receive the training?

The people in your organisation who operate or use AI systems, and those who do so on your behalf without being employees, such as contractors or service providers (Article 4). It does not have to be the same for everyone: the measures are tailored to each person's knowledge, experience and training and to the context the AI is used in.

The Commission reads "other persons dealing with the operation and use of AI systems on their behalf" as people within your organisational remit who are not employees: a contractor, a service provider or even a client, and accepts different training levels per group. It also warns that, in many cases, asking staff to read the instructions for use may be ineffective. People with a degree or experience in AI development normally count as AI-literate, though it is worth checking that they know your organisation's specific systems and their legal and ethical aspects. For high-risk systems, Article 26(2) additionally requires the people exercising human oversight to have the necessary competence, training and authority.

Reviewed: Read the full guide →

What should AI literacy training cover?

At a minimum, that your staff understand what AI is and how it works, which AI systems your organisation uses, and what their opportunities and risks are. According to the Commission, from there it is tailored to your organisation's role (provider or deployer), to the risk of the systems and to what each person already knows.

Article 4, as worded by Regulation (EU) 2026/1744, asks you to take into account people's technical knowledge, experience, education and training and the context the systems are used in. The Commission adds that simply asking staff to read the instructions for use may be ineffective, and that people using generative tools to, for example, draft or translate text should know specific risks such as hallucination. In practice a common module for everyone plus one per role is usually enough: people who use AI daily, people who review its output before it goes out, and people who decide which tools are approved.

Reviewed: Read the full guide →

How do I show I comply with Article 4, and can I be fined?

With an internal record of trainings and other initiatives: the Commission states that no certificate and no specific governance structure are required. National authorities supervise Article 4 from 2 August 2026 and may impose penalties or other measures, taking into account proportionality and the nature, gravity and intentionality of the infringement.

A useful record notes who received which training and when, which AI systems each group uses, and what material or policy they were given; the linked training-plan template does that. You do not need to appoint an AI officer or set up a board to comply with Article 4, although one can help organise it. If you also process personal data with AI, the same record helps demonstrate accountability under GDPR Article 5(2).

Reviewed: Read the full guide →

Full guide: AI literacy and internal AI policy · All FAQs