Create AI training based on roles: AI Act, GDPR and obligation to provide evidence
Since February 2, 2025, Art. 4 AI Act requires operators and providers to have sufficient AI competence. Anyone who does not structure training in a role-based, documented and GDPR-compliant manner risks fines and supervisory orders. This guide shows the structure.
Since February 2, 2025, Article 4 of Regulation (EU) 2024/1689 (AI Act) obliges providers and operators of AI systems to ensure a sufficient level of AI competence among their staff and other persons who operate or use AI systems on their behalf. This obligation applies to every company that uses ChatGPT, Microsoft Copilot, Google Gemini, Claude or specialised AI software, regardless of industry or size. According to Art. 99 AI Act, fines range up to 35 million euros or 7% of the global annual turnover, depending on which amount is higher.
This guide shows how role-based AI training is specifically set up according to the AI Act and GDPR: which roles need which content, how evidence is verifiably documented, what integration with Art. 30 GDPR and Art. 32 GDPR is required and how the appointment certificate, reporting line and Audit templates make the whole thing audit-proof. The appointment certificate, signed, filed, verifiable. The article is aimed at those responsible for IT, data protection, compliance and human resources who want to set up an auditable training path in four to six weeks without reinventing the wheel at every step. The practical structure follows the CIVAC methodology with workspace, 490 audit templates and a defined reporting line to management.
Key Takeaways
- Since February 2, 2025, Art. 4 AI Act requires documented AI competence from all people who use AI systems on behalf of the company.
- Role-based AI training separates providers, operators, users and data protection officers with different mandatory content and depth.
- Evidence of the participant list, training slide version, test and appointment certificate from the AI manager is indispensable in the audit.
Legal framework: Art. 4 AI Act and interface to the GDPR
Art. 4 AI Act requires providers and operators of AI systems to take measures to ensure a sufficient level of AI competence of their staff and other persons working with AI systems on their behalf, taking into account their technical knowledge, experience, education and training, as well as the application context and those affected. This regulation has been in effect since February 2, 2025. Unlike Article 39 GDPR, the AI Act does not name a specific role such as the DPO, but rather requires an organisation-wide competence base. The connection to the GDPR results from Art. 32 GDPR (technical and organisational measures) and Art. 35 GDPR (data protection impact assessment in the event of a likely high risk).
In concrete terms, this means: Anyone who trains or fills a GenAI application with personal data triggers two mandatory paths. Firstly, the AI competence according to Art. 4 AI Act, secondly, the data protection risk assessment including training according to Art. 39 GDPR. The EU Commission made it clear in the guidelines of May 5, 2025 that both obligations have a cumulative effect. Anyone who has appointed an external data protection officer should sensibly link the AI training to the annual GDPR training, but supplement it with independent role-based modules. Without this double anchoring, an auditable gap arises that supervisory authorities have been explicitly addressing since the beginning of 2026. The EU AI Act does not superimpose the GDPR, it supplements it with its own competence and documentation requirements along the AI life cycle. Those who map both regimes in a uniform training architecture avoid duplication of work and create the consistent evidence path that supervisory authorities are increasingly demanding. Deadline begins as soon as we become aware of it. The training obligation is organisational and cannot be delegated, even if the operational implementation is carried out by external providers.
Define roles: provider, operator, user, representative
Role-based AI training begins with a clear role definition according to the AI Act and organisation. Art. 3 AI Act distinguishes between providers and operators (deployers) as well as other actors along the supply chain. Companies that only use GenAI tools are usually operators. Anyone who develops their own models or substantially adapts them becomes a provider. Four training groups are added within the company: firstly, end users (e.g. sales, marketing, service), secondly, AI power users (e.g. data analysis, IT architecture), thirdly, AI managers or AI officers (control, risk assessment), fourthly, management and supervisory functions such as DPO, ISB and compliance.
Each group needs its own training content, its own depth of training and its own test questions. An end user must understand which data is allowed in which tool, what hallucination risks exist and when a final human check is mandatory according to Art. 14 AI Act. An AI officer must be able to assess risk classes in accordance with Articles 6, 7 and Annex III of the AI Act, coordinate data protection impact assessments and report obligations to the supervisory authority. CIVAC provides a dedicated template in the workspace for each role, so that the training is completed in four weeks instead of four months. Licence the workspace for your internal representatives or have our representatives order it. The platform manages participant lists, version statuses of training slides and automatic reminders for follow-up training. There is also a role matrix that connects the personnel base, function, depth of training and resubmission date and thus generates the supervisory certificate at the push of a button. The separation of provider and operator roles is relevant to the audit because the catalogues of obligations differ greatly and incorrect assignments can lead to fines. Anyone who builds their own models or substantially adapts them automatically falls into the role of provider with an additional conformity assessment obligation according to Art. 43 AI Act.
Understanding risk classes: from prohibited systems to GPAI
The AI Act classifies AI systems into four risk classes: prohibited practices (Article 5), high-risk systems (Article 6 and Annex III), systems with transparency requirements (Article 50) and systems with minimal risk. A fifth category includes models with general purpose AI (GPAI) according to Articles 51 and 52, with independent obligations for providers starting from thresholds of 10^25 FLOPs. Anyone who sets up AI training in the company must operationalize this classification. Employees must be able to recognise that, for example, an AI system for employee selection in recruiting is to be classified as a high-risk system according to Annex III No. 4 and thus triggers additional obligations for conformity assessment, logging obligations according to Article 12 and impact assessment according to Article 27.
The training does not have to convey this logic perfectly in legal terms, but it does have to make it operational: which tool can be used for what, which inputs are taboo, who makes which decision, where is it documented. A pragmatic training course uses concrete examples from everyday company life, a classification matrix and a clear escalation rule for the compliance officer or the AI manager. CIVAC delivers the classification matrix as an audit template, pre-filled for 22 typical use cases from sales, HR, IT, marketing and service. This reduces the company-specific adjustment effort to around two working days instead of the usual three to four weeks of in-house research. Anyone who combines the classification logic with concrete tool examples in the training concept achieves a significantly higher retention rate in learning goal monitoring. Audit-proof, documented, § 6-proof. In addition, a short negative list of tools and use cases that are expressly prohibited in the company helps to combine training content with an operational ban. This negative list is stored in a versioned manner in the workspace and is automatically checked every time a new tool is released.
Training content per role: what really needs to be taught
End users need three core issues. First: data protection when prompting. Never enter personal data from patients, customers, applicants or employees into non-approved tools, as this data is usually processed outside the EU data space and Art. 44 GDPR is triggered. Second: recognise hallucinations. AI systems generate plausible but false statements, which is why every safety or legal statement must be checked against a reliable source. Third: Transparency obligations according to Art. 50 AI Act, especially when customers are confronted with chatbots or AI-generated content.
AI power users also need knowledge about training data hygiene, bias risks, logging requirements, data protection impact assessment and security measures according to Art. 15 AI Act. Those responsible for AI must also be aware of the obligations as operators according to Art. 26 AI Act: human supervision, data quality, logging, conformity checks and reporting obligations in the event of serious incidents according to Art. 73 AI Act within 15 days. Management and supervisory bodies need less detail, but clarity about liability, fine risks and decision-making authority. A compliance platform and officer-as-a-service bundles this content as a modular curriculum with clearly defined learning goals, tests and version statuses, so that the annual repetition does not act as occupational therapy, but rather as escalation training in accordance with the AI Act and GDPR. Audit-proof, documented, § 4-proof. Licence the workspace for your internal representatives or have our representatives order it. CIVAC provides a ready-to-use module for each of the four roles, including slides, e-learning variant, test, answer sheet and template for the certification to the supervisory authority. Anyone who conducts training without testing is documenting participation, not competence. The supervisory authority has been increasingly checking this difference since 2026 and no longer accepts mere confirmations of attendance as sufficient proof. The tests are versioned for each role so that the content on the training date can still be verified in the audit.
Evidence management: participant lists, tests, versions
The most common oversight question in AI training is not whether, but how it will be demonstrated. Three artifacts are essential. Firstly, a list of participants with name, function, training date, training duration and signature. Secondly, a version status of the training slides or e-learning module with date, list of sources and person responsible for the update. Thirdly, a test or learning goal control that provides evidence that the training result has actually reached the participant. A mere attendance list is not enough because it says nothing about the competence imparted.
In the CIVAC workspace, these three artifacts are linked to the respective role, the processing directory in accordance with Art. 30 GDPR and the risk classification of the AI systems used. This results in a verifiable trace from the specific training day to the specific processing activity. The auditor calls, the evidence is ready. Anyone who appoints a compliance representative links the AI training register to the annual compliance reporting to the management. In addition, the system stores learning success rates for each role so that those responsible for AI can specifically address weaknesses in the following year. This preparation closes the most common oversight gap in AI training in the design phase and makes the training path reproducible at the push of a button. The platform differentiates between compulsory training, voluntary in-depth training and event-related follow-up training, so that the audit makes it clear which measure is assigned to which legal framework. Others run compliance like a filing cabinet. We run it like software. In the case of an exam, this structural quality is more decisive than the sheer number of training hours because it clearly separates purpose, content and goal achievement and combines them in a verifiable way. A written justification for the training decision for each role supplements the documentation and significantly shortens questions from supervisors.
Interlocking with GDPR obligations and processing directory
AI systems regularly process personal data, which is why the processing directory must be supplemented with AI-specific fields in accordance with Art. 30 GDPR. Specifically: legal basis for data processing in the model, data categories, recipients (particularly for third country transfers according to Art. 44 ff. GDPR), retention periods, security measures used, reference to the associated data protection impact assessment and to the risk classification according to the AI Act. AI training must make these fields known to users so that a new AI use case does not start without an entry in the directory.
The AI fields are already created in the workspace as an extension of the GDPR processing directory. Every new AI use case automatically receives a mandatory check against Art. 4 AI Act (competence), Art. 5 (prohibited practices), Art. 6 and Annex III (high risk), Art. 27 (impact assessment) and Art. 35 GDPR (data protection impact assessment). Only after a positive check is the use case added to the productive directory. This integration is not optional, it is the substance of what the supervisory authority assesses as lived AI governance. Others run compliance like a filing cabinet. We run it like software. The training path leads directly to the operational release process for new AI applications and closes the circle between learning, action and evidence. In addition, the data protection impact assessment according to Art. 35 GDPR is carried out with the impact assessment according to Art. 27 AI Act in a common template, so that redundant assessments are eliminated. Anyone who previously maintains the processing directory as Excel will replace it during the migration with a structured system with versioning, responsible persons and follow-ups without losing the inventory. The migration typically takes two business days and is included in the SLA.
Appointment certificate for AI representative and reporting line
The AI Act itself does not contain a mandatory obligation to appoint an AI representative like Art. 37 GDPR does for the DSB. However, Article 26 of the AI Act does require operators of high-risk systems to ensure human supervision, maintain logs, monitor compliance and report serious incidents. These obligations cannot be fulfilled operationally without designated responsible persons. In practice, larger companies voluntarily appoint an AI officer, often with a dual reporting line to management and compliance, in addition to the data protection officer. The appointment certificate regulates the scope of tasks, escalation channels, representation, remuneration and confidentiality.
CIVAC provides this appointment certificate as an audit template, ready for use by GmbH, AG, KGaA and public bodies. The reporting line is documented in the workspace, supplemented by substitution regulations, response time SLA and annual activity report. Anyone who has already appointed the information security officer will link the content of the AI officer role to the ISMS according to ISO/IEC 27001:2022, since many obligations from Articles 15 and 26 AI Act can be technically mapped via the 93 controls of the ISMS. This creates a consolidated governance structure in which AI, data protection and IT security have a common reporting line to management instead of coexisting and creating duplication of work. The appointment certificate, signed, filed, verifiable. The platform stores the appointment certificate, activity report and escalation path in an audit-proof manner and makes the status visible to management on a single overview page. This gives the management level a complete overview of compliance at all times, without any questions or distributed file research. Anyone who manages the AI representative role with ISB and DSB in a uniform platform avoids frictional losses and interface errors in the design phase, long before the first supervisory request.
Deadlines, fines, supervisory practice 2026
The most important deadlines of the AI Act apply staggered. Prohibited practices according to Article 5 and the obligation to have AI competence according to Article 4 have been applicable since February 2, 2025. Obligations for providers of GPAI according to Art. 51 ff. have been effective since August 2, 2025. High-risk obligations from Annex III apply from August 2, 2026, high-risk obligations from Annex I from August 2, 2027. The following applies to each deadline: Anyone who misses the deadline risks fines of up to 35 million euros according to Art. 99 AI Act or 7% of group turnover for prohibited practices, up to 15 million. Euros or 3% for violations of other obligations and up to 7.5 million euros or 1% for incorrect information provided to authorities.
As of now, national supervision in Germany lies with the Federal Network Agency as the central AI supervisor, supplemented by sectoral authorities such as BaFin, BfDI and the state data protection authorities. A first wave of official inquiries about AI competence has been documented since the beginning of 2026, particularly in industries with high GenAI use such as insurance, banking, pharmaceuticals and human resources services. Anyone who works in these industries without proof of training not only risks a fine, but also conditions that prohibit the operation of the AI systems until further training. Deadline begins as soon as we become aware of it. Consistent training documentation significantly reduces this escalation risk and shortens the clarification time in the audit from days to hours. Anyone who combines the training requirement from Article 4 with the appointment certificate logic of those responsible for AI builds the evidence path once and uses it annually. This lead time is critical in 2026 before the high-risk deadline of August 2, 2026.
Turn reading into an assignment
Role-based AI training is not a spring PowerPoint appointment, but a permanent governance path. It begins with a role matrix, continues through risk classification, training modules and tests and then interlinks with a processing directory, data protection impact assessment and AI use case approval. Anyone who builds this path without a platform ties up months of internal resources. Anyone who sets it up with a platform can be tested in four to six weeks and drastically reduces the annual maintenance time. The decisive factor is the choice between self-construction on the CIVAC platform and officer-as-a-service with an AI representative appointed by CIVAC.
Licence the Workspace for your internal representatives or have our representatives appointed. Both models provide the same audit-proof, documented, Section 4-proof trail of evidence. CIVAC is a compliance platform and officer-as-a-service with EU data residency, ISO/IEC 27001:2022-ISMS, 490 audit templates, 25 officer roles and defined 2-business-day SLA. Turn reading into an assignment. Write to info@civac.de or use the contact form on civac.de. You will receive a role matrix, a modular training curriculum and an appointment certificate template for the AI manager within two working days. This means that entry into AI Act compliance is planned in a concrete, timeable and verifiable manner. Anyone who initiates the start now will have a complete role matrix, documented training with tests, an appointed AI manager and a linked processing directory within four to six weeks. The auditor calls, the evidence is ready. It is precisely this speed that distinguishes verifiable compliance from a formal training folder.
FAQ
When does the obligation to have AI competence apply according to Art. 4 AI Act?
The obligation to ensure sufficient AI competence has been directly applicable since February 2, 2025. It affects every provider and operator who uses AI systems in the company, regardless of the industry, size or risk class of the system used. The obligation must be fulfilled organisation-wide, cannot be delegated to external tool providers and must be proven with documented evidence for each person.
What fines are there if there is no AI training?
According to Art. 99 AI Act, fines of up to 15 million euros or 3% of the global annual turnover are imposed for violations of the operator's obligations, and up to 35 million euros or 7% for violations of Art. 5 (prohibited practices). Supervisory authorities can also issue orders to suspend AI operations until proof of training has been fully provided.
Do we have to formally appoint an AI representative?
The AI Act does not require a formal order like Art. 37 GDPR. In practice, however, an appointment certificate makes sense in order to clarify responsibilities, establish a reporting line to management and prove in the audit that the obligations under Article 26 AI Act have been fulfilled. CIVAC provides a tested appointment certificate template, ready for use by GmbH, AG and public bodies.
How do we integrate AI training with our existing GDPR training?
A combined annual training course with two independent modules is common. Module A covers GDPR obligations, Module B covers the AI Act-specific content. The participant list, test and version status are documented together, but the content is verified separately so that both supervisory regimes can find the respective evidence clearly. CIVAC supplies prefabricated interlocking modules with identical logic.
Which roles need which level of training?
End users require 60 to 90 minutes of basic training per year. AI power users need three to four hours of technical content. AI managers and representatives need eight to sixteen hours of in-depth study of risk classification, DPIA and reporting requirements. Management receives a two-hour briefing on liability, fines and escalation procedures, supplemented by a short written certificate.
How long is AI training valid?
There is no statutory maximum duration, but good practice is to repeat annually, adapting to new tools, use cases and supervisory practices. In the event of significant changes such as the introduction of a high-risk system or a new GenAI platform, ad hoc follow-up training with a documented reason and proof of participation is required. The resubmission is automatically scheduled in the workspace.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.