EU AI Act Masterclass, Part Two
Almost every company can produce an AI policy. Very few can produce the evidence underneath it, and the policy is not what anyone is actually asking for.
Executive brief
A policy is a promise. Evidence is a receipt. Regulators, boards and insurers have stopped collecting promises
Article 4 has applied since February 2025 and was not deferred. Whatever else moved, this one is live
Attendance records alone do not clear the bar. What counts is who, on what, when, whether it matched their role, and whether they absorbed it
The vendor clause vendors resist hardest is the one obliging them to cooperate when your regulator, client or insurer asks you to prove something
At renewal, underwriters are already asking for the AI inventory, the classifications, the training evidence and the incident process
Episode conversation
Watch the episode
The difference between an AI policy and evidence of AI compliance
Ask a company whether it governs its AI and you will usually get a document. Ask it to prove the document is true and the room goes quiet.
Ahmed draws the line in one move. A policy is a promise. Evidence is a receipt. Regulators, boards and insurers are not in the business of collecting promises, and they stopped being impressed by them a while ago.
His analogy is the one worth stealing. A policy is a menu. It tells you what is theoretically on offer. What an inspector actually wants is the recipe: what goes into the dish, who made it, and whether the kitchen passed its last check. As he put it, what is the regulator or your board going to do with the menu? It is good marketing material. It is not proof of anything.
There is a test in there you can run on your own company this afternoon. If somebody asked you tomorrow to show rather than tell, what could you physically hand over? If the honest answer is a PDF, you have a menu.
The annexes of the EU AI Act set out what the documentation is expected to contain, so this is not a matter of guessing what would satisfy someone.
What counts as evidence under Article 4 of the EU AI Act
Article 4 requires providers and deployers to make sure the people working with their AI systems have a sufficient level of AI literacy. It has applied since 2 February 2025, and when the Digital Omnibus pushed most of the high-risk obligations out to December 2027, Article 4 was not among them. Whatever else moved on the calendar, this one is live now.
The wording says train your people. What it means in practice is train your people and be able to prove you did.
Ahmed starts with the business case rather than the legal one, which is the right order. If you have five thousand people, or twenty-five thousand, with new hires arriving and existing staff changing roles, how would you even know whether your workforce meets a minimum standard? You would not. So the first thing you need is a record that tells your HR team who has reached the baseline and who has not, because if you are not bringing people to that standard you are letting them down before you are letting any regulator down.
From there, what counts as evidence:
Element | What it captures |
Attendance | Who was actually in the room. |
Training content | What they were taught, not just that they were taught. |
Role-based tiers | Whether the training matched what that person actually does with AI tools. |
Assessment results | Whether any of it landed. |
Refresh dates | How long ago, and when it is due again. |
He is blunt about why attendance on its own does not clear the bar. Plenty of people attend training. Not everybody pays attention. So he adds a quiz, and where the role is genuinely critical, a full assessment, and only once somebody has demonstrated competence at a basic level do they get to resume the part of the job that touches the tool. Otherwise that person becomes a single point of failure.
His comparison is a hydraulic hammer. You would not hand one to somebody who had never been trained on it and hope they worked out the button. They would take the factory apart. AI tools carry comparable force in the wrong hands and almost none of the same handling requirements, which is the part that should bother people more than it does.
And then the line that belongs on a wall somewhere: a certificate nobody can find is a policy. It is not proof.
Why documented training becomes a mitigating factor when something goes wrong
Ahmed points out that these questions are not hypothetical, because privacy regulators already ask them. When there is a breach and you report it, one of the first things you get asked is when you last trained your staff, specifically the staff involved in the incident, and whether you can share the details. Nobody should be surprised by that question. It is standard.
If you can demonstrate a real training programme, it acts as a mitigating factor when a penalty is being set.
His point holds. The numbers around it are worth getting right, because the Act does not have a single fine ceiling. It has three tiers.
Tier | Maximum | What it covers |
One | EUR 35 million or 7% of global annual turnover, whichever is higher | Prohibited AI practices under Article 5 |
Two | EUR 15 million or 3% of global annual turnover | Most other obligations, including AI literacy, transparency and deployer duties |
Three | EUR 7.5 million or 1.5% of global annual turnover | Supplying incorrect, incomplete or misleading information to authorities |
For SMEs and start-ups the lower of the two figures applies rather than the higher. And Article 99 requires authorities to weigh mitigating and aggravating factors when they set an amount, which is where the training evidence earns its keep. The record is not a nice-to-have you produce afterwards. It is the thing that moves the number.
The five clauses to demand from every AI vendor contract
This is the most immediately usable part of the conversation. Ahmed names five things he wants in writing from any general-purpose AI vendor before a deal gets signed.
# | Clause | Why |
1 | Documentation and compliance information available on demand | Article 53 already obliges providers of general-purpose AI models to make this available. Getting it into the contract makes the duty flow to you in writing rather than in theory. |
2 | Notice of substantial modifications or purpose changes before they ship | This is the Article 25 problem from part one. A substantial modification can promote you from deployer to provider without anybody in your company having decided to become one. |
3 | A warranty of AI Act compliance for their role, with indemnity | They say they are compliant and they put money behind it. If you are fined for something that was theirs to handle, the indemnity is what stops it becoming your problem. |
4 | Incident and malfunction notification inside a fixed window | So you find out in days rather than in six months, while you still have time to protect your staff, your users and your customers. |
5 | Audit and evidence support | They cooperate when a regulator, a client or an insurer asks you to prove something. |
The clause vendors resist hardest
Ahmed is realistic about why vendors push back at all. Your point of contact is usually somebody on the sales side who wants the deal closed and the commission booked, so the reflex is to say you can sort all that out later. His advice is to not accept that. Later is how this ends up unresolved and in your file.
The harder case is a power imbalance. Walk up to a hyperscaler with a list of demands and you will be shown the standard terms and told to take them or leave them. The consolation is that the largest vendors already have AI governance teams, already understand the requirements, and already want to sell into Europe, so the documentation frequently exists whether or not they will negotiate the paper.
The one they push back on hardest is the fifth. Nobody wants to be contractually pulled into your conversations with a regulator. As Ahmed put it, everybody would like to stay invisible to the regulator, which is exactly why the clause matters.
And the stakes on that fifth clause run in three directions. If a regulator asks you for something and you cannot produce it because your vendor will not hand it over, that counts as an aggravating factor against you. If an important client makes a reasonable request you cannot meet, you lose the client or you lose money. And if your insurer asks and you cannot answer, you either pay a higher premium or, in the worst version, you find out that the risk you thought you had transferred was never transferred at all.
How fast should an AI vendor tell you something broke
There is no universal number here, and Ahmed does not pretend otherwise. It depends entirely on how business-critical the system is and what the consequences look like if it goes wrong.
But there is a reference point. GDPR says a processor must notify without undue delay, which on its own means nothing operationally. So in his own contracts, Ahmed defines it. Twenty-four to forty-eight working hours, pushed to seventy-two at the absolute outside.
The reasoning is simple arithmetic. The sooner you know, the cheaper the fix and the fewer people get hurt. The longer it sits, the more both of those numbers move in the wrong direction.
Then he gives the example that makes it concrete. Say you are in pharmaceuticals and you are using an AI system to help determine the correct dose going into a drug. Those get shipped to hospitals and clinics and people start taking them more or less immediately. Now say there is a glitch. How comfortable are you finding out about it in six months? What is your appetite, exactly? Ten people harmed, a hundred, a million, none? Answer that honestly with your risk team, check what your insurance actually covers, and then write the notification window that matches the answer. That is the process. Not a number somebody copied out of a template.
Where to start if your company has done nothing about AI governance
Four steps, in this order.
First, get clarity, because without it you cannot make confident decisions about anything else. That means an inventory of every AI system in the business, including the shadow ones nobody registered and everybody is quietly using. You cannot classify what you have not found.
Second, classify what you found. Twice over. Once against the four risk tiers covered in part one, where limited risk is the tier most people skip past and the one that should have their attention right now.
The second classification is the one companies get wrong. Ahmed lists five roles a business can play under the Act: provider, deployer, importer, distributor, and authorised representative. The Act’s own definition of an operator adds product manufacturer as a sixth. None of them are mutually exclusive, and every obligation attached to every role you are playing applies to you at once.
"A certificate nobody can find is a policy. It is not proof."
Jamal Ahmed
One tool, three hats
A UK firm buys an AI tool built in the US. That makes it the importer. It white-labels the tool for its own clients. Now it is also the provider. It uses the same tool internally for hiring. Now it is the deployer as well. One purchase, three roles, three rule books, and a company that almost certainly believes it is just a user.
That belief is the whole problem. Most organisations assume they are users with no obligations. A meaningful number of them are already providers and do not know it.
Third, check what you found against the banned list. Anything on it stops the day you find it.
Fourth, assess your AI literacy needs, start the training, and document the evidence as you go rather than reconstructing it later under pressure.
What happens when insurers start pricing AI risk separately
This is the part that should get a CFO’s attention.
Right now, AI risk sits quietly inside general liability and umbrella policies. Not many carriers price it separately. Not many ask hard questions about it at binding. Which means, as Ahmed puts it, a great many companies are currently insured for AI entirely by accident.
Renewal is where that arrangement ends. Underwriters have already started asking for the AI inventory, the classifications, the evidence of training, and the incident management process. Every single thing covered in this conversation, arriving as a questionnaire with a premium attached to the answers.
And what satisfies an underwriter is not a policy document. It is an independent, measurable assessment. The question they are asking is not whether you have written something down. It is whether you can evidence the controls.
The training gap runs all the way to the board
Jeff’s observation at the close of the conversation is the one that reframes everything above. The AI fluency problem is not confined to the people using the tools. Boards are being asked to oversee AI risk without the fluency to understand what they are overseeing, which means the training obligation does not stop at the staff who touch the systems. It runs from the bottom of the company to the top of it.
Which brings the whole conversation back to a measurement problem. Somebody is going to ask your board to prove it. The regulator, the enterprise customer, the underwriter at renewal. They are all asking a version of the same question, and none of them will accept the menu.
Is your AI investment making money or losing money?
TheAIAudit measures your organization’s collective AI investment and returns a single AI Health Score from 0 to 100, with three statements behind it that say what to fix: Governance, Impact, and Risk Flow.
Apply for the founding cohort
Questions answered in this episode
What is the difference between an AI policy and evidence of AI compliance?
A policy is a promise and evidence is a receipt. A policy describes what a company intends to do. Evidence proves it happened, and it is what regulators, boards and insurers actually ask for. Ahmed’s test: if somebody asked you tomorrow to show rather than tell, what could you physically hand over?
What counts as evidence of AI literacy training under Article 4?
Five things: attendance records, the training content itself, role-based tiers showing the training matched what that person does with AI tools, assessment results demonstrating they absorbed it, and refresh dates. Attendance alone does not clear the bar, because plenty of people attend training and not everybody pays attention.
Was Article 4 of the EU AI Act delayed by the Digital Omnibus?
No. Article 4 has applied since 2 February 2025 and was not among the obligations deferred to December 2027. Whatever else moved on the calendar, the AI literacy duty is live now.
What clauses should a company demand from an AI vendor?
Documentation and compliance information on demand, notice of substantial modifications or purpose changes before they ship, a warranty of AI Act compliance with indemnity, incident and malfunction notification inside a fixed window, and audit and evidence support. The fifth is the one vendors resist hardest, because it contractually pulls them into your conversations with a regulator.
How quickly should an AI vendor be required to report an incident?
There is no universal number, and the right window depends on how business-critical the system is. As a reference point, GDPR requires notification without undue delay. Ahmed defines that in his own contracts as twenty-four to forty-eight working hours, pushed to seventy-two at the absolute outside.
What are underwriters asking for when they price AI risk?
The AI inventory, the risk and role classifications, evidence of training, and the incident management process. What satisfies them is an independent, measurable assessment rather than a policy document. The question is not whether you have written something down, it is whether you can evidence the controls.
Chapters
00:00 Insured by accident
00:25 Why the loudest voices in AI are often the least qualified
01:23 Meet Jamal Ahmed
02:43 A policy is a promise, evidence is a receipt
03:33 The menu and the recipe
04:23 Article 4: what actually counts as evidence
06:30 The hydraulic hammer
07:16 A certificate nobody can find
08:09 Why training records become a mitigating factor
09:14 Why vendors push back
10:30 Five clauses to demand before you sign
14:12 The clause vendors resist hardest
14:31 How fast should a vendor tell you something broke
16:26 The pharmaceutical dosing example
18:01 Starting from zero: the first four moves
19:05 Five roles, and the company wearing three at once
21:17 How a European regulation actually gets made
23:42 How AI risk is insured today
24:22 What an underwriter will ask you for
24:57 Why boards lack the fluency to oversee this
Sources
The EU AI Act
Regulation (EU) 2024/1689. eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
The Digital Omnibus on AI
Regulation (EU) 2026/1744, in force 27 July 2026.
The clauses referenced in this episode
Article 4 on AI literacy, Article 25 on responsibilities along the AI value chain, Article 53 on obligations for providers of general-purpose AI models, and Article 99 on penalties.
Jamal Ahmed’s guide
The Easy Peasy Guide to the EU AI Act. amazon.co.uk/dp/1917534175