CASE STUDY
How Pepco was able to comprehensively manage employee training with an LMS
WEBINAR
Master AI in isEazy Author in under an hour.
GUIDE
Prepare your organization to comply with the new AI regulations
Stay up to date with all our latest news
Subscribe to our newsletter Stay up to date with all our latest news
September 3, 2026
CONTENT CREATED BY:

Table of contents
The EU AI Act (Regulation EU 2024/1689) is the world’s first comprehensive law regulating artificial intelligence. It entered into force in August 2024 and is rolling out its obligations in phases through to 2028. As of today, several are already enforceable: the ban on unacceptable AI practices since February 2025, the AI literacy requirement also since February 2025, and transparency obligations since August 2026. If your organisation uses AI — even occasionally — it already falls within the scope of this regulation.
The AI Act establishes a common legal framework for the development, commercialisation and use of artificial intelligence systems in the European Union. Unlike a directive, it is a regulation: it requires no national transposition and has been directly applicable in all EU member states since it entered into force on 1 August 2024.
Its central logic is proportionality to risk: the greater the potential impact of an AI system on people, the stricter the obligations. This translates into a four-tier classification — unacceptable, high, limited and minimal risk — which determines what each organisation must comply with, based on how and why it uses AI.
The AI Act is not designed solely for large tech companies. It applies to any organisation that develops, distributes or simply uses AI systems — from a customer service chatbot to a tool that filters CVs or analyses employee performance. If AI makes or supports decisions affecting people within the European market, the regulation applies, regardless of the company’s size or headquarters.
From an HR and corporate training perspective, the AI Act introduces a particularly relevant obligation: Article 4 requires organisations to ensure AI literacy for all staff working with AI systems. This requirement has not been postponed and has been in force since February 2025.
The AI Act groups all artificial intelligence systems into four categories according to the risk they pose to people. This classification determines which obligations apply and when they become enforceable.
| Risk level | Examples in a business context | Key obligations |
|---|---|---|
| Unacceptable (prohibited) | Social scoring, emotion recognition in workplaces or educational settings, real-time biometric identification in public spaces | Absolute prohibition since February 2025. No technical adaptation is possible. |
| High risk (Annex III) | CV screening, AI-based performance evaluation, credit scoring, AI-driven decisions in education | Risk management, data governance, technical documentation, human oversight. Applicable from December 2027 (Digital Omnibus). |
| Limited risk | Customer service chatbots, AI-generated content, deepfakes in communications | Transparency obligations (Art. 50): users must be informed when interacting with an AI. Enforceable since August 2026. |
| Minimal risk | Spam filters, content recommendation systems, AI in video games | No specific AI Act obligations beyond the general transparency and literacy requirements. |
Regulation (EU) 2026/1744, known as the Digital Omnibus, was published in the Official Journal of the EU on 24 July 2026. It introduces a partial but highly significant delay for organisations using AI: the obligations for high-risk AI systems listed in Annex III — covering employment, education, credit and essential services — have been moved from 2 August 2026 to 2 December 2027. Systems listed in Annex I (embedded in regulated products such as medical devices or machinery) have been pushed back to 2 August 2028.
However, the Digital Omnibus did not delay everything. The transparency obligations under Article 50 and the AI literacy requirement under Article 4 remain enforceable from August 2026. Treating the Omnibus as a general pause is the most common misinterpretation — and the one most likely to leave organisations exposed to enforcement action.
The AI Act is being applied in stages. This is the current state as of August 2026, incorporating the changes introduced by the Digital Omnibus:
| Date | What comes into force |
|---|---|
| 1 August 2024 | The AI Act enters into force as a European Regulation. Adaptation period begins. |
| 2 February 2025 | Ban on unacceptable-risk systems (Art. 5). AI literacy obligation (Art. 4) becomes enforceable for all organisations. |
| 2 August 2025 | Obligations for general-purpose AI (GPAI) models, such as GPT or Claude. AESIA gains sanctioning powers over prohibited practices. |
| 2 August 2026 | Transparency obligations (Art. 50): notify users when AI is involved, label AI-generated content. AESIA holds full inspection competencies. |
| 2 December 2027 | High-risk AI systems listed in Annex III (employment, education, credit). Deadline extended by the Digital Omnibus (previously: August 2026). |
| 2 August 2028 | High-risk AI systems listed in Annex I (medical devices, machinery). Deadline extended by the Digital Omnibus. |
The AI Act does not distinguish by company size or sector. It applies to two main categories of actor:
The regulation also has extraterritorial reach: a company headquartered outside the EU is still subject to the AI Act if its systems are used or have an effect within the European market.
A common misconception is that the AI Act only targets large technology companies. It does not. Any organisation that uses AI — even a third-party tool embedded in its standard software — falls within the scope of the regulation. In practice, this includes the majority of mid-sized and large companies operating in Europe today.
Annex III of the AI Act identifies eight areas where AI use is considered high-risk due to its potential impact on individuals:
For these sectors, high-risk obligations apply from December 2027 following the Digital Omnibus. However, transparency and literacy requirements are already enforceable now.
To understand the specific risks of AI use in corporate training, this article covers the key blind spots that organisations frequently overlook.
The AI Act’s penalty regime is one of the most stringent in European regulation — surpassing even the GDPR at its highest tier. Fines are structured across three levels based on the severity of the breach:
For SMEs and startups, Article 99(6) provides a proportionality mechanism: the lower of the fixed amount and the turnover percentage applies — not the higher. Even so, for a company with €5 million in revenue, a serious breach could still result in a fine of up to €150,000.
Beyond financial penalties, non-compliance can lead to a market withdrawal order for the AI system in question, restrictions on use, and significant reputational damage at a time when trust in AI has become a key decision criterion for customers and business partners.
In Spain, the authority responsible for supervision and enforcement is AESIA (Agencia Española de Supervisión de la Inteligencia Artificial), based in A Coruña. Since August 2026 it holds full inspection competencies over transparency obligations and can open formal sanctioning proceedings.
For a broader view of how to approach regulatory compliance from a training and organisational perspective, see our article on compliance management.
Complying with the AI Act is not solely a legal or technical matter — it has a mandatory training dimension that falls directly within the remit of HR and L&D teams.
Article 4 of the AI Act requires both providers and deployers to ensure a sufficient level of AI literacy among their staff and any third parties operating AI systems on their behalf. This obligation has been in force since 2 February 2025 and was not postponed by the Digital Omnibus.
The regulation does not prescribe a specific certification or minimum number of hours, but it does require that training be proportionate to each employee’s role and the risk level of the AI system they use. According to European Commission data, 78% of companies still do not have a documented AI literacy plan in place.
AESIA can request evidence of the training programme in the context of an inspection. A record that includes participants, content, dates and completion evidence is the minimum recommended documentation.
Article 4 literacy training is not a prompt engineering workshop. It aims to ensure that employees understand what an AI system can and cannot do, what risks it introduces, what biases it may carry, and what it means to use it responsibly in each specific context. A compliant AI literacy programme should cover:
Beyond strict compliance, the regulation encourages organisations to build a culture where AI is used ethically and responsibly. This means embedding concepts such as algorithmic fairness, data governance and the traceability of automated decisions into training programmes.
Organisations that treat AI literacy as a strategic investment — rather than a compliance checkbox — reduce operational incidents, improve the quality of AI-assisted decisions, and build a genuine competitive advantage in a market that increasingly rewards technological trust. For a broader view of how generative AI is reshaping corporate learning, see our article on generative AI: what it is, how it works, and how to use it responsibly.
Article 4 requires proportionality: not all employees need the same depth of training. This table provides a starting point for structuring your AI literacy plan:
| Profile | Recommended training level | Key content areas |
|---|---|---|
| Basic user (any employee who uses AI tools) | Essential AI literacy | What AI is, its limitations, basic biases, when not to trust the output, individual rights. |
| Middle manager / decision-maker | Advanced AI literacy | Risk classification, human oversight, algorithmic ethics, how to document AI-assisted decisions. |
| HR / L&D professional | AI Act and HR specialisation | High-risk AI in employment, Art. 4 and the training plan, Art. 50 and transparency, GDPR alignment, AESIA. |
| AI system administrator / internal AI provider | Technical specialisation | Technical documentation, risk management (Art. 9), data governance (Art. 10), EU database registration. |
Complying with the AI Act is entirely manageable if approached in the right order. These are the four steps recommended by the European Commission and AESIA as a starting point:
In parallel, organisations using high-risk AI systems have until December 2027 to bring their risk management, data governance and technical documentation processes into compliance. The extension is not a pause — it is time to get it right.
AI Act compliance does not start in the legal department — it starts with training. Article 4 places L&D teams at the centre of regulatory compliance, and the isEazy Skills catalogue includes content specifically designed to meet this obligation.
Pepco, a retail company present in more than 20 European countries, is an example of an organisation that invested in AI training as a cultural transformation lever before the regulation became fully enforceable. Working with isEazy, they built a scalable digital training programme for thousands of employees across multiple countries.
Find out how they did it →
The isEazy Skills AI Academy offers a course catalogue covering artificial intelligence, digital responsibility, technology ethics and algorithmic bias prevention — designed to address the competency areas that Article 4 of the AI Act identifies as necessary. Content is kept up to date with the current regulatory framework and can be assigned by employee profile, making it straightforward to meet the proportionality requirement the regulation demands.
isEazy Skills combines microlearning, social learning and gamification to achieve high completion rates, even in environments with high turnover or geographically dispersed teams. Courses are available in multiple languages, accessible on any device, and generate activity records that can be used as documentary evidence in an AESIA inspection.
Organisations that approach AI literacy as a strategic investment — not just a compliance requirement — are building teams that are better equipped to use AI safely and responsibly. In a market where trust in AI is increasingly a supplier and partner selection criterion, training becomes a genuine competitive differentiator. With isEazy Skills, EU AI Act compliance can also be the foundation for a culture of responsible innovation.
The European AI regulation is not a threat on the horizon — it is a framework already in force. As of today, the prohibitions are active, the AI literacy obligation has been enforceable for over a year, and transparency requirements have applied since August 2026. The Digital Omnibus has given organisations more time for high-risk systems, but it has not paused a single obligation that was already in effect.
For HR and L&D teams, this means that AI Act compliance runs substantially through training. A documented AI literacy plan, segmented by employee profile and aligned with the risk level of the systems each team uses, is today the first line of defence against a potential AESIA inspection — and the foundation for the organisation to use AI with judgement and responsibility.
Organisations that act early will not just avoid penalties: they will be better positioned to capture the opportunities AI offers in a regulated environment. AI Act compliance can be the starting point for a culture of responsible innovation that, over the medium term, becomes a genuine competitive advantage.
If you want to know where to begin, isEazy can help you design the AI training plan your organisation needs to comply with Article 4 and prepare your teams for the new regulatory landscape. Request an isEazy Skills demo →
The EU AI Act (Regulation EU 2024/1689) is the world’s first comprehensive legal framework for artificial intelligence. It entered into force on 1 August 2024, with obligations phasing in gradually: prohibitions from February 2025, rules for general-purpose AI models from August 2025, and transparency and AI literacy requirements from August 2026. As a European regulation — not a directive — it requires no national transposition and applies directly in all EU member states.
The AI Act applies to any company that develops or uses AI systems within the European market, regardless of size or headquarters location. It also has extraterritorial reach: companies based outside the EU are still subject to it if their AI systems affect the European market. Two main categories are covered: providers (those who develop or place AI on the market) and deployers (those who use third-party AI in their internal processes). If your company uses an AI-powered applicant tracking system, a chatbot, or any automated decision-making tool, you are likely a deployer with your own obligations under the regulation.
The Digital Omnibus (Regulation EU 2026/1744), published in the Official Journal of the EU on 24 July 2026, introduced a significant but partial delay for certain AI obligations. Specifically, it postponed the requirements for high-risk AI systems listed in Annex III — which includes systems used in employment, education, credit, and essential services — from 2 August 2026 to 2 December 2027. Systems in Annex I (integrated into regulated products such as medical devices or machinery) were pushed back to 2 August 2028. However, the Digital Omnibus did not delay the transparency obligations under Article 50 or the AI literacy requirements under Article 4, both of which have been enforceable since August 2026.
Article 4 of the AI Act requires both providers and deployers to ensure a sufficient level of AI literacy among their staff and any third parties operating AI systems on their behalf. This obligation has been in force since 2 February 2025 and was not postponed by the Digital Omnibus. The regulation does not mandate a specific certification or minimum number of training hours, but training must be proportionate to each employee’s role and the risk level of the AI system they use — a generic company-wide course does not meet the standard. Critically, the programme must be documented, as the relevant national authority (in Spain, AESIA) can request evidence of AI literacy plans during an inspection.
The AI Act’s penalty regime is among the strictest in European regulation — exceeding even the GDPR at its upper end. Fines are structured across three tiers based on the severity of the breach. Using prohibited AI systems or violating the bans under Article 5 can result in fines of up to €35 million or 7% of global annual turnover (whichever is higher). Breaches of other substantive obligations — including Article 50 transparency requirements — can reach €15 million or 3%. Providing incorrect or misleading information to supervisory authorities carries fines of up to €7.5 million or 1%. For SMEs and startups, Article 99(6) provides proportionality: the lower of the fixed amount and the turnover percentage applies. In Spain, the competent authority is AESIA.
AESIA (Agencia Española de Supervisión de la Inteligencia Artificial — the Spanish Agency for the Supervision of Artificial Intelligence), established by Royal Decree 729/2023 and headquartered in A Coruña, Spain, is the national authority designated to supervise and enforce the AI Act in Spain. It has held sanctioning powers over prohibited practices since August 2025, and as of August 2026 it has full inspection competencies covering transparency and AI literacy obligations. If a company fails to comply, AESIA can open investigation procedures and ultimately impose the fines set out in the Regulation. Companies operating in Spain should treat AESIA as the primary regulatory contact for AI compliance matters.
WEBINAR
Master AI in isEazy Author in under an hour.
Register Now
