Internal AI Policy for Businesses: How SMEs Comply with the AI Literacy Obligation Under Article 4 of the EU AI Act
Since 2 August 2026 the Bundesnetzagentur actively monitors AI literacy compliance. What an AI policy needs – with a concrete structure template.
Since 2 August 2026 the EU AI Act has been fully in force — and the Bundesnetzagentur (Germany's Federal Network Agency) has taken up its role as the central market surveillance authority. The AI literacy obligation under Article 4 has, however, been binding since 2 February 2025: any business deploying AI systems must ensure that the staff involved understand what they are working with. What changed in August 2026 is that this obligation can now be actively inspected.
A trade business in Recklinghausen using ChatGPT for quotations, an engineering firm in the Ruhr region using Copilot for project documentation, a law practice running AI-assisted research tools — all are operators under the Regulation. Without a written AI policy and documented training measures, there is no evidence to present when the authority comes asking.
Note: This article provides a practical overview and does not constitute legal advice. For your specific situation, please seek qualified legal counsel.
What Article 4 of the AI Act Actually Requires
Article 4(1) of the EU AI Act (Regulation (EU) 2024/1689) obliges providers and deployers to take measures to ensure, to their best extent possible, a sufficient level of AI literacy among staff and others dealing with the operation and use of AI systems on the company's behalf.
The wording is deliberately flexible. There is no prescribed number of training hours, no mandatory certification and no official template curriculum. The provision expressly takes into account the technical knowledge, experience and education of those involved, as well as the specific deployment context. A three-person business does not need to build an internal AI governance office.
In practice, the obligation means: the team should understand how the tools work in principle, where their limitations lie, what data may be entered — and what must never be.
One important detail: the obligation extends to contractors and third-party service providers who operate AI systems on the company's behalf. Outsourcing an AI project does not automatically relieve the client of responsibility.
The Omnibus Package: An Important Correction
The Digital Omnibus package on the AI Act entered into force on 27 July 2026 and slightly softened Article 4 without deferring it. The original requirement to "ensure" staff possess adequate AI literacy was changed to "support the development of AI literacy". This softer formulation applies retroactively from the original effective date of 2 February 2025.
What this means in practice: the obligation is now somewhat less absolute. You do not have to guarantee that every employee reaches a particular competency level. But you must be able to show that you have taken proportionate measures — policy, training, documentation. A business that can produce nothing at an inspection is in a weak position.
The Omnibus package did, however, defer the obligations for high-risk AI systems (Annex III) from August 2026 to December 2027 or August 2028. For most SMEs that use only commercial AI tools such as ChatGPT or Copilot, Articles 4 and 50 remain the two most immediately relevant obligations — and both continue to apply unchanged.
Twelve Essential Elements of an AI Policy
An internal AI usage policy is the core document for Article 4 compliance. It does not need to be a legal treatise — one to three pages are sufficient for most small businesses. These twelve elements should be included:
- Purpose and scope — who the policy applies to, which tools and use cases it covers
- Roles and responsibilities — who acts as internal AI contact, who delivers training, who updates the policy
- Permitted tools (whitelist) — approved AI systems with stated purpose, contract status and confirmation that a data processing agreement (DPA) is in place
- Prohibited uses — what must not be done, in particular the prohibited AI practices listed in Article 5 of the Act (e.g. social scoring, subliminal manipulation)
- Data classification — what may be entered? Recommended: four tiers (public / internal / confidential / personal data) with concrete examples in each
- Prompt rules — explicit list of off-limits data: customer names, health information, passwords, trade secrets, ongoing legal matters
- Output responsibility — who reviews AI-generated content before it is used or published? No unreviewed AI text in official documents
- Labelling (Article 50) — how and where AI-generated content must be identifiable as such; chatbots must disclose that the user is speaking to an AI
- Training records — reference to the training programme and the obligation to document attendance (name, date, topics covered)
- Incident handling — what to do if an AI tool loses data, erroneous outputs enter critical processes, or a data protection incident occurs
- Works council / co-determination — reference to § 87(1)(6) German Works Constitution Act (BetrVG): AI tools capable of monitoring employee behaviour require a works agreement
- Review cycle — recommended: every six months or whenever new tools are introduced
Free templates based on this structure are available from the Mittelstand-Digital Zentrum Berlin and the German chambers of commerce (IHK).
On the data protection side: the GDPR continues to apply alongside the AI Act — it is not replaced. Anyone entering personal data into AI tools still needs a Data Processing Agreement. How this works in practice for ChatGPT, and what business accounts offer, is covered in my post on DSGVO-compliant use of ChatGPT.
Making Training Auditable: What the Authority Wants to See
Regulators do not require certification — they require documentation. A three-tier structure has proven effective:
- Tier 1 – all AI users (1–2 sessions): how AI works, its limitations, hallucination risks, data protection basics, company policy walkthrough
- Tier 2 – regular users (3–5 additional sessions): tool-specific training, prompt quality, quality-checking AI outputs
- Tier 3 – AI leads and managers (10–20 sessions): governance, risk assessment, regulatory compliance, handling communications with supervisory authorities
What makes training auditable: a sign-in record listing names, dates and topics covered. This list must be available in the event of an inspection. A one-off training session from 2023 or 2024 is not sufficient — the rapid pace of AI development requires regular updates.
The European Commission maintains a repository of more than 40 real-world AI literacy practice examples at digital-strategy.ec.europa.eu — but explicitly states that replicating those examples does not constitute a presumption of compliance with Article 4.
Who Enforces This in Germany — and Since When
The Bundesnetzagentur has been Germany's central AI Act market surveillance authority since 2 August 2026, established under the Gesetz zur Marktüberwachung und Innovationsförderung von Künstlicher Intelligenz (KI-MIG), which entered into force on 29 July 2026. Sector-specific responsibilities coexist: BaFin for financial services, the Federal Institute for Drugs and Medical Devices (BfArM) for AI in medical products, and the BSI for IT security aspects of AI systems.
No confirmed fines under the AI Act have been publicly reported since enforcement began in August 2026. Analysts expect the first concluded proceedings in 2027, following the pattern seen after the GDPR, where significant fines arrived roughly 18 months after the law became enforceable.
Article 4 itself does not appear in the penalty catalogue (Article 99 of the Act). This means there is no standalone fine for the absence of an AI policy. However, a business that violates another obligation — such as the Article 50 transparency requirement — and can demonstrate no competency measures whatsoever, risks a more severe assessment by the authority. Fines for Article 50 violations can reach up to €15 million or 3 percent of worldwide annual turnover — whichever is lower for SMEs.
For a full overview of which obligations have been in effect since 2 August 2026 and which follow only in 2027 or 2028, see my EU AI Act overview for SMEs.
Five Questions We Hear Regularly
Does every small business need an AI policy?
Yes, as soon as AI tools are used in the business — including on employees' private accounts for work purposes. The question is not whether, but how extensive the policy needs to be. A two-person business can manage with half a page; a mid-sized company with 80 staff needs more depth.
Is a brief team email enough?
No. An email is not a policy document and does not constitute documented training. You need a written set of rules that your team has read and signed, along with a training attendance record.
What about ChatGPT Free — is that allowed?
In default settings, OpenAI trains the model using inputs from Free accounts. For business use, at least a Team or Business account with a DPA is recommended. For a comparison of what GDPR-compliant alternatives offer, see this overview.
Is there an official government template?
No binding one. The European Commission publishes practice examples on its website (which do not confer compliance). Free, practically usable templates are available from the Mittelstand-Digital Zentrum Berlin and the IHK chambers of commerce.
Does the training obligation also apply to apprentices and external contractors?
Yes. Every person who operates or uses AI systems in the course of the business's activities falls within the scope of Article 4 — regardless of the employment relationship.
If you would like to discuss what an AI policy for your business should look like in practice — from a medical practice to a manufacturing company in the Ruhr region — I am happy to talk through it in a first conversation. You can find out what AI consulting with me looks like and how we can get started.
Note: The articles on this blog are produced with the help of AI and are editorially reviewed before publication. Editorial responsibility lies with Emre Yurtbay (see the Impressum).