Most mid-market companies believe a signed AI policy covers them. Inspectors beginning their rounds in August will ask for training records tied to named people, not policy documents. This guide is about that gap, and how to close it before anyone asks.
Get the free guideThis guide is for HR, compliance, L&D, and AI leaders across the business, not just the teams building AI. If your company uses commercial tools such as Copilot, ChatGPT, or Gemini and has assumed the law mostly applies to companies that build their own AI systems, this guide is about closing that gap.
If your product is the AI itself, Article 4 still applies to your own teams on top of your provider obligations, and it is usually the piece high-risk companies overlook while focused on the compliance work already in front of them.
What Article 4 actually requires, and why having a policy does not satisfy it on its own.
Why using commercial AI tools, without building your own, still creates deployer obligations under the law.
The three things that feel like compliance and are not: the policy-only company, the one-off course, and access without training.
What an inspection actually checks, and the specific records and documentation inspectors ask to see.
What a defensible training programme looks like, in what order, and what it costs to build one.
Where risk concentrates inside a typical mid-market company, and why one generic course cannot cover all of it.
Helping mid-market companies build AI literacy, capabilities & transformation. Designed and delivered by 100+ female industry experts.
Companies we've worked with
A free guide that translates the EU AI Act into what your company needs to do, and the records that prove you did it.