OpenAI Shelves GPT-6.1 Astra After Safety Tests: What Went Wrong?
OpenAI shelved GPT-6.1 Astra after safety tests flagged scope, authorization and action-reporting issues. See what is confirmed and what remains...
Explore EU AI Act compliance for managers, including AI literacy requirements, role-based training, risk governance, transparency, human oversight, implementation timelines, training evidence, and practical strategies for building an effective AI governance culture across organizations today.
Managers do not need to become AI lawyers, but they do need enough AI literacy to make sound decisions about how their teams use AI, recognize when a use case needs specialist review, and apply organizational AI policies in practice.
Article 4 of the EU AI Act requires providers and deployers to take measures supporting the development of AI literacy among relevant staff and other people operating or using AI systems on their behalf. Following the 2026 Digital Omnibus amendment, the obligation is explicitly context-sensitive and does not require an organization to guarantee a specific level of AI literacy for every individual.
For managers, that makes role-based training especially relevant. This guide explains what EU AI Act compliance for managers means, what useful training should cover, how managers can support organizational compliance, and which implementation dates matter now.
The EU AI Act places obligations on defined actors, particularly providers and deployers, rather than creating a universal legal category called "manager."
Under Article 3 of the AI Act, a provider generally develops or has an AI system developed and places it on the market or puts it into service under its own name or trademark. A deployer is a natural or legal person, public authority, agency, or other body using an AI system under its authority, except for personal non-professional use.
In many companies, the legal person, not an individual department manager, is the deployer. Managers can nevertheless influence procurement, deployment, employee use, oversight, risk escalation, and implementation of internal controls.
For the broader organizational framework, see EU AI Act compliance.
An individual manager is not automatically a separate deployer merely because employees in their team use AI.
The European Commission's current Article 50 guidance explains that where a legal person is the deployer and employees act under its instructions and control, those employees should not be treated as separate deployers. The same principle can extend to contractors operating the system on the legal person's behalf and under its responsibility and control.
Managers should therefore distinguish between:
organizational legal obligations, which attach to the relevant provider, deployer, or other regulated actor;
managerial responsibilities, such as applying internal policies, supervising workflows, identifying questionable uses, and escalating concerns; and
specialist responsibilities, where legal, compliance, privacy, security, HR, procurement, or technical expertise is needed.
An organization may also hold different AI Act roles for different systems.
Managers often sit between organizational policy and day-to-day AI use. They may approve a tool, decide whether an AI-assisted workflow is appropriate, supervise employees relying on AI outputs, or respond when a system creates an unexpected risk.
The AI Act defines AI literacy in terms of skills, knowledge, and understanding that support informed AI deployment and awareness of AI opportunities, risks, and possible harms.
For a manager, useful AI literacy therefore goes beyond prompt writing. It includes knowing what a system is being used for, where human judgment remains necessary, which uses require approval, and when to involve a specialist team.
Article 4 requires providers and deployers to take measures that support the development of AI literacy among relevant staff and other people dealing with AI systems on their behalf.
The current consolidated EU AI Act on EUR-Lex says those measures should take account of technical knowledge, experience, education, training, the context in which systems are used, and the people or groups on whom they are used. It now expressly states that providers and deployers do not have to guarantee any individual's specific level of AI literacy.
That wording supports a role-based approach rather than identical training for every employee.
Article 4 focuses on staff and other people dealing with the operation and use of AI systems on behalf of providers or deployers.
The European Commission's AI literacy Q&A explains that "other persons" can extend beyond employees to people within the organization's operational remit, such as contractors or service providers, depending on the circumstances.
A practical organization might therefore distinguish between general AI users, managers, developers, procurement staff, HR teams, compliance professionals, and personnel operating systems with heightened risks.
The law does not require all of these groups to receive identical content.
No. The EU AI Act does not prescribe one commercial course, private certification, training provider, or fixed number of training hours for Article 4.
The Commission says there is no one-size-fits-all mandatory training format and no requirement for a specific certificate. It also states that organizations can keep internal records of training or other guidance initiatives.
A certificate can be useful evidence of course completion. It should not be represented as proof that an organization has satisfied every applicable AI Act requirement.

Effective EU AI Act compliance training for managers should translate regulation into decisions they may actually face.
A useful learning outcome is not simply "understands the AI Act." A manager should leave training better able to recognize an AI-related governance issue, ask appropriate questions, apply internal policy, and escalate matters they should not decide alone.
Managers need a working understanding of AI systems, generative AI, common workplace applications, and important limitations.
Training should address inaccurate or fabricated outputs, inappropriate reliance on automation, confidentiality risks, potential bias, and the difference between using AI to assist a human decision and allowing AI to determine an outcome.
For example, a customer-service manager allowing staff to draft replies with generative AI should understand what data may be entered, how outputs are reviewed, and whether customers are directly interacting with an AI system.
Manager training should explain the Act's risk-based structure without becoming a full legal course.
Managers should understand:
the provider and deployer distinction;
prohibited AI practices;
the basic concept of high-risk AI;
Article 50 transparency obligations;
relevant general-purpose AI concepts; and
why intended purpose matters when assessing a system.
The Commission's current overview confirms that high-risk classification depends on the system's function and intended purpose, not simply the industry using it.
Managers should understand how their organization identifies risks, assigns ownership, approves AI use, monitors systems, establishes oversight, and handles escalation.
For high-risk systems, Article 26 requires deployers, once the relevant requirements apply, to assign human oversight to people with the necessary competence, training, authority, and support.
That makes oversight a practical management issue, not merely a theoretical AI principle.
AI governance and data protection frequently overlap, but they are not the same compliance exercise.
Manager training should explain organizational rules for entering personal or confidential information into AI tools, handling AI-generated outputs containing sensitive information, and escalating questions to privacy, legal, or security teams.
It does not need to turn managers into GDPR specialists.
Article 50 has applied since 2 August 2026 to specified AI interactions and AI-generated or manipulated content.
The European Commission's Article 50 transparency guidance covers obligations concerning direct AI interaction, machine-readable marking of certain synthetic content, emotion recognition and biometric categorisation, deepfakes, and certain AI-generated public-interest text. Different duties apply to providers and deployers, and exceptions can apply.
A marketing manager publishing AI-generated material, for example, should know when the workflow may raise an Article 50 question and when to seek specialist review.
Managers who need a structured way to build this knowledge can explore AI Governance Courses' EU AI Act Compliance Training. Training is one component of a wider governance program and does not by itself establish organizational compliance.
Managers should start with a practical question: what AI is my team using, for what purpose, and what decisions or people can it affect?
From there, manager-level responsibilities typically include following organizational policies, supporting appropriate AI literacy, maintaining meaningful oversight, identifying unusual or higher-risk uses, and involving specialist functions when required.
The following is a practical management framework, not a statutory allocation of legal duties:
|
Situation |
What the manager should ask |
Practical next step |
|
Team proposes a new generative AI tool |
What is its intended use, what data will enter it, and is it approved? |
Follow procurement, security, privacy, and AI governance processes |
|
AI influences recruitment or employee evaluation |
Could this fall within an Annex III employment use case? |
Escalate to HR, legal/compliance, and AI governance |
|
AI-generated content will be published externally |
Could Article 50 transparency requirements apply? |
Review disclosure requirements with the appropriate owner |
|
Employees routinely accept AI recommendations |
Is effective human oversight expected? |
Review the workflow, authority, and escalation arrangements |
|
A vendor materially changes an AI feature |
Has the intended purpose, functionality, or risk changed? |
Trigger reassessment where appropriate |
|
Employees use unapproved AI tools |
Do policies cover the actual use taking place? |
Identify the use and apply the organization's approval process |
Before approving or recommending an AI product, managers can ask:
What business purpose will the system serve?
What data will employees provide to it?
Will its output influence decisions about people?
What is the vendor's stated intended purpose?
Has the tool completed the organization's required security, privacy, procurement, or governance review?
What happens if the vendor changes the system materially?
A vendor's marketing claim that a product is "AI Act compliant" should not replace the organization's own assessment of its role and use.
Employment-related AI deserves particular attention.
Annex III includes defined use cases involving recruitment, candidate evaluation, certain decisions affecting work relationships, task allocation based on individual behaviour or characteristics, and performance monitoring.
That does not mean every HR system containing AI is automatically high-risk. Article 6 includes conditions under which some Annex III systems may fall outside high-risk classification where they do not pose a significant risk or materially influence decision-making, although systems performing profiling of natural persons remain high-risk under Article 6(3).
Managers should escalate consequential HR AI use rather than attempting to make the legal classification alone.
Managers should know who owns which type of question.
Legal or compliance teams may need to interpret regulatory applicability. Privacy teams handle personal-data issues. Security teams address access, confidentiality, and technical security. Procurement manages supplier processes. HR becomes relevant for workforce use. Technical or AI governance teams may need to evaluate system behaviour, limitations, monitoring, and oversight.
Good managerial AI literacy includes knowing when a decision has moved beyond normal operational judgment.
The implementation timetable changed materially when Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026. The Digital Omnibus text on EUR-Lex amended Article 4 and postponed important high-risk application dates.
|
Date |
What it means for managers |
|
2 February 2025 |
Article 4 AI literacy measures and the original prohibited-practice rules began applying. The current Article 4 wording was later amended, but the AI literacy obligation remains. |
|
2 August 2025 |
AI governance provisions and obligations for providers of general-purpose AI models began applying. |
|
2 August 2026 |
Article 50 transparency obligations began applying, subject to a limited transition described below. The AI Act also reached its general application date for many other provisions. |
|
2 December 2026 |
The limited transition for Article 50(2) machine-readable marking and detection ends for relevant generative AI systems placed on the market before 2 August 2026. |
|
2 December 2027 |
Core Chapter III requirements for relevant high-risk systems classified through Article 6(2) and Annex III are scheduled to apply. |
|
2 August 2028 |
Chapter III requirements for relevant high-risk systems associated with the Article 6(1) and Annex I product pathway are scheduled to apply. |
The Commission's Article 4 Q&A states that the AI literacy obligation has applied since 2 February 2025 and that supervision and enforcement rules apply from 3 August 2026 onwards.
For Article 50, the Commission confirms that the rules generally apply from 2 August 2026, while relevant pre-existing generative systems receive the narrow Article 50(2) transition until 2 December 2026.
Managers should therefore treat AI literacy and applicable transparency requirements as current matters while preparing relevant operations for the later high-risk deadlines.
A practical approach to implementing EU AI Act compliance begins with actual AI use, not a generic course catalogue.

Map approved AI tools, generative AI services, and AI features embedded in existing software.
Also create a route for identifying informal or unauthorized use. The purpose is not to assume that "shadow AI" is widespread, but to avoid making governance decisions from an incomplete inventory.
Separate learners according to what they actually do.
Useful groups may include general employees, managers, technical teams, compliance and legal functions, procurement, AI operators, and personnel working with potentially higher-risk systems.
Consider the factors reflected directly in Article 4: technical knowledge, experience, education, training, context of use, and the people potentially affected.
A software engineer operating an internal development tool and an HR manager overseeing AI-assisted recruitment are unlikely to need identical learning objectives.
Manager training should emphasize judgment and governance.
By the end of training, a manager should be better able to:
recognize an AI use case that requires escalation;
understand the provider/deployer distinction at a practical level;
apply internal AI policies;
identify potentially sensitive or higher-risk contexts;
support meaningful human oversight;
ask relevant vendor questions; and
know which specialist function to involve.
The Commission itself uses different learning packages for generalists, managers, and developers, illustrating how differentiated training can work in practice.
Organizations may consider retaining:
participant and completion records;
training dates;
course or module content;
learning objectives;
policy acknowledgements;
assessment results where used; and
review or refresh dates.
This is a practical evidence-management approach, not a prescribed Article 4 record format.
The Commission expressly states that Article 4 does not require a certificate and says organizations can maintain internal records of training and other guidance initiatives.
AI literacy should evolve when systems, business use cases, staff responsibilities, internal policies, or regulatory guidance change.
Updates should be triggered by meaningful changes, not simply by an arbitrary annual calendar. A new AI-enabled HR function, significant vendor change, or revised Commission guidance may justify review sooner.
When evaluating EU AI Act training courses, check whether the training is current, role-specific, and practical rather than simply asking whether it mentions Article 4.
A stronger manager course should help learners make and escalate decisions, not merely recall definitions.
|
Evaluation area |
Less useful approach |
Stronger manager-focused approach |
|
Article 4 |
Quotes the provision |
Connects literacy to role, context, systems, and affected people |
|
Manager relevance |
Generic employee awareness |
Approval, oversight, procurement, and escalation scenarios |
|
Regulatory currency |
Static overview |
Identifies current amendments and update date |
|
Practical exercises |
Recall-only quiz |
Realistic management and escalation scenarios |
|
Governance |
Abstract principles |
Explains interaction with legal, privacy, HR, security, and procurement |
|
Completion evidence |
Implies certification equals compliance |
Records learning without overstating legal effect |
|
Updates |
No clear process |
Explains how regulatory changes are incorporated |
The following is a practical training-design distinction, not a set of levels mandated by the EU AI Act.
|
Area |
General employee training |
Manager-focused training |
|
Basic AI literacy |
Core |
Core |
|
Safe AI use |
Core |
Core |
|
AI risk awareness |
Basic |
Deeper |
|
Governance |
Limited |
Stronger |
|
Oversight |
Basic |
Stronger |
|
Escalation |
Basic |
Detailed |
|
AI policy implementation |
Limited |
Stronger |
|
Strategic decision-making |
Limited |
Relevant |
Use this manager-level list alongside a fuller EU AI Act compliance checklist. Completing it does not by itself establish legal compliance.
Identify the AI systems used by your team.
Understand each system's intended business purpose.
Know the relevant organizational AI policies.
Confirm that appropriate AI literacy measures are in place.
Identify sensitive, consequential, or potentially higher-risk uses.
Understand the organization's escalation procedures.
Check whether relevant transparency considerations have been addressed.
Coordinate with legal, privacy, security, HR, procurement, or AI governance specialists when appropriate.
Maintain proportionate evidence of training and relevant governance activity.
Review changes in systems, responsibilities, and regulation.
One common mistake is treating training as a one-time compliance checkbox. AI literacy needs to remain connected to the systems people actually use.
Other avoidable problems include giving every role identical training, equating AI literacy with prompt-writing skills, assuming a certificate proves compliance, ignoring unapproved AI use, confusing provider and deployer obligations, and assuming every AI system is high-risk.
Managers should also avoid making specialist legal classifications alone. Their role is often to recognize the issue early and get the right expertise involved.
AI literacy is most useful when it connects directly with governance.
Managers help turn policies into working practices by linking training with procurement, privacy, security, risk management, oversight, monitoring, and escalation. That connection also makes training easier to update because new AI use cases can feed directly into the organization's learning program.
The goal is not to make every manager an AI Act specialist. It is to ensure managers have enough knowledge and organizational support to make responsible operational decisions and recognize when specialist review is needed.
The Act does not prescribe a universal manager course. Article 4 requires providers and deployers to take measures supporting AI literacy while considering factors such as knowledge, experience, training, use context, and affected people. Manager-focused training is one practical way to address those factors.
Article 4 requires AI literacy measures, but it does not say that a standardized training course is the only permitted approach. The Commission recognizes training, guidance, and other appropriate literacy initiatives, depending on context.
No. The Commission states that there is no Article 4 requirement for a specific certificate.
The Article 4 obligation concerns staff and other people dealing with AI systems on behalf of providers and deployers. Appropriate measures can differ substantially according to their roles, knowledge, and the systems involved.
Manager training should normally cover practical AI fundamentals, relevant AI Act concepts, organizational policy, AI risk, oversight, transparency awareness, confidentiality and privacy considerations, escalation, and manager-specific governance decisions.
Start with the AI systems people actually use and the responsibilities they hold. Then tailor learning according to knowledge, experience, context, system risk, and the people who may be affected.
Organizations can maintain proportionate internal evidence such as participants, completion dates, training content, learning objectives, policy acknowledgements, and review dates. The EU AI Act does not prescribe one universal Article 4 documentation template.
Different provisions apply on different dates. AI literacy has applied since 2 February 2025, Article 50 transparency rules generally since 2 August 2026, relevant Annex III high-risk requirements from 2 December 2027, and relevant Annex I product-related high-risk requirements from 2 August 2028.
Managers involved in procuring, approving, supervising, or using potentially high-risk systems should understand enough to recognize when high-risk classification may be relevant and when specialist assessment is required. They do not necessarily need to perform the legal classification themselves.
The Act does not prescribe a universal refresher interval. A practical approach is to review training when AI systems, use cases, employee responsibilities, internal policies, or regulatory guidance materially change.
OpenAI shelved GPT-6.1 Astra after safety tests flagged scope, authorization and action-reporting issues. See what is confirmed and what remains...
AI Law
Learn AI compliance requirements, key risks, the EU AI Act, NIST AI RMF, ISO 42001, and practical steps to build...
AI Law
Understand AI regulation in the United States in 2026, including federal rules, state AI laws, privacy, discrimination and practical compliance...