Back to the kit

Evidence Kit · Samples

Full samples, nothing held back

These are complete documents, generated for a fictional company — Northwind Talent, a recruiter whose CV-ranking tool lands in Annex III point 4. Nothing is truncated and nothing is watermarked. If they are not worth paying for, you will know before you pay.

Placeholders marked [to be completed] are deliberate: they are the points where only you can supply the fact, and a blank invites the conversation that a confident guess would skip.

Sample. Fictional organisation and system. Do not use this as your own record — the reasoning in it belongs to a company that does not exist.

AI literacy plan

Northwind Talent GmbH, HRB 998877, Berlin

For the compliance owner and whoever delivers training; the completed records are the Article 4 evidence.

1. What Article 4 actually requires now

Art. 4 as amended by Reg. (EU) 2026/1744

Article 4 expects providers and deployers to ensure a sufficient level of AI literacy among the staff and other people dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training, and the context in which the systems will be used.

The obligation has applied since 2 February 2025, alongside the Article 5 prohibitions. It is not affected by the Chapter III deferral.

Organisation
Northwind Talent GmbH, HRB 998877, Berlin
Plan owner
Jana Novak — Head of People Operations, acting AI compliance owner
Population in scope
51-250 people using AI tools at work
Plan date
2026-09-11
Refresh cycle
Annual, plus on joining and on any material change in the tools used

2. Who needs to know what

Proportionality means different roles get different depth. At your size role-based tiers are worth the effort, because a blanket session pitched at everyone is pitched at nobody.

GroupNeeds to understandDepthEvidence
Everyone using AI toolsWhat the tools are, what must never be entered into them, that they remain responsible for the output, how to report a problemOne session of 45–60 minutes, plus the usage policy acknowledgementAttendance record and signed acknowledgement
Managers and team leadsThe above, plus how a general tool drifts into a high-risk use case, and that a named person takes decisions about peopleThe general session plus a 30-minute briefingAttendance record
Anyone deploying customer-facing AIArticle 50 disclosure duties and the exact wordings we useWalk-through of the disclosure kitSign-off in the disclosure implementation log
Assigned human overseers of high-risk systemsThe system's limitations and failure modes, automation bias, when and how to override or stop it, and the logging dutyStructured training against the provider's instructions for use, with a competence checkNamed competence record per Article 26(2)
Compliance ownerThe classification framework, the register, the deadlines, and what changes trigger a reassessmentOngoing — this kit, plus change alertsThis plan and the register

3. Curriculum

  1. What the AI Act is and who it applies to — provider versus deployer, and why we can be both. Where we currently sit.
  2. The prohibitions: the eight practices under Article 5(1)(a) to (h), plus the two that apply from 2 December 2026. Framed as "never do this", with examples from our own work.
  3. Transparency in practice: what we must tell people, the wordings we use, and why claiming human review that did not happen is worse than no claim at all.
  4. Confidentiality and personal data: what must never be pasted into a tool, why data that leaves does not come back, and the approved-tools register.
  5. Judgement: hallucination, fluency as a risk signal, automation bias, and the rule that a named person takes any decision that affects a person.
  6. Reporting: what to report, to whom, and the assurance that prompt reporting is never itself misconduct.
  7. Role-specific module for overseers of the high-risk system: its limitations, its failure modes, and how to intervene.

Keep it concrete. The single most effective segment in this kind of training is five real examples from your own organisation — two where AI helped, two where it produced something confidently wrong, and one near-miss with confidential data.

4. Delivery and records

ActivityAudienceOwnerDueCompletedRecord held
Induction sessionAll AI tool usersJana Novak[to be completed][to be completed][to be completed]
Usage policy acknowledgementAll staff in scopeJana Novak[to be completed][to be completed][to be completed]
Manager briefingManagers and team leadsJana Novak[to be completed][to be completed][to be completed]
Overseer competence trainingNamed overseersJana Novak[to be completed][to be completed][to be completed]
New joiner moduleJoiners, within first monthJana NovakOngoing[to be completed][to be completed]
Annual refreshAll AI tool usersJana Novak[to be completed][to be completed][to be completed]
This table is the deliverable. Article 4 asks for a sufficient level of literacy; what you can actually show a regulator, a customer or an insurer is a completed row with a date and a name against it.

Attendance record

Northwind Talent — AI literacy session
Date: ____________  Delivered by: ______________________
Modules covered: ________________________________________

Name                          Role                          Signature
______________________        ______________________        ______________________
______________________        ______________________        ______________________
______________________        ______________________        ______________________

Plan owner

Approved by

Date

What a lawyer should check

Hand this list to counsel with the document. It is short on purpose — these are the points where a generated record most often diverges from the facts of a real organisation.

  1. Whether training obligations interact with works council or employee consultation requirements in your Member State.
  2. Whether the competence record for named overseers is specific enough to satisfy Article 26(2) for this particular system.
  3. Whether professional bodies in your sector impose their own AI competence requirements beyond Article 4.
  4. Whether any vendor contract already obliges you to train users in a particular way.
  5. This document is a structured record of an assessment you made, drafted for your review. It is not legal advice and it does not bind any authority.
  6. It reflects Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (the "Digital Omnibus on AI"), in force 27 July 2026. The Commission's guidelines on high-risk classification under Article 6(5) were due on 2 February 2026 and remain in draft (version of 19 May 2026), so classification positions that depend on them may change.
  7. No harmonised standard has yet been cited in the Official Journal, so the presumption of conformity in Article 40 is not available to anyone.
Generated by euai-act.com — a documented self-assessment, not legal advice.

Generate these for your own system

Run the free Navigator to classify your system, then the kit fills these documents in from your answers.