ServicesSafe AIWorkAboutWebsitesContactGet your free plan

Do you need an AI policy? What the EU AI Act asks of small companies

6 October 2026

Owners ask me whether they need an AI policy, usually expecting the answer to involve a certification course or a new hire with a title like AI officer. It doesn't. Here is what the EU AI Act actually asks of a small company, as of the Commission's guidance, and what I'd put on a one-page policy instead of worrying about the rest.

This comes up most often after someone has read a headline about the AI Act and assumed it means a heavy compliance project. For a small company just using AI tools day to day, it usually doesn't. The part that applies to almost everyone is narrower and more manageable than the headlines suggest.

What Article 4 actually requires

Article 4 of the AI Act is the AI literacy requirement, and it applies to providers and deployers of AI systems, which covers most companies using AI tools in any capacity, not just ones building them. As of the Commission's guidance, there is no certificate to obtain and no specific training level mandated. An internal record of the training or guidance you have already given staff is enough to satisfy it.

There is no requirement for an AI officer or a governance board. If you run a small company and someone on your team has shown colleagues how to use a tool properly, and you can point to that happening, you are closer to compliant than most owners assume.

Article 4 was amended by the Digital Omnibus on AI, in force mid-July 2026. The obligation to ensure AI literacy stays in place, but the amendment confirms there is still no specific training level mandated. The direction of travel has been toward less prescriptive, not more, which is worth knowing if you have been putting this off out of fear of a moving target.

What this means in practice is that the requirement is about the outcome you reach, rather than a specific process for reaching it. The point is that people using AI tools in your company understand roughly what those tools can and can't do, and where the risks sit. How you get them there, a short briefing, a written note, a conversation, is left to you.

What a plain one-page policy contains

I tell clients to keep this to one page, because a policy nobody reads is worse than no policy, in the sense that it gives you false confidence without changing anyone's behaviour.

Allowed tools: name the specific tools staff can use for work, rather than leaving it open-ended. If someone wants to try a new one, that's the next line.

What data never goes in: customer data, contracts, anything confidential. This overlaps with the kind of traffic-light thinking I cover on the safe AI page, and it is the single most useful line on the page.

Who to ask before adopting a new tool: one name, one way to ask. Without this, people adopt tools quietly because asking feels like friction.

A review note: a line saying when this was last looked at and by whom. It doesn't need to be complicated, it needs to exist.

That's five lines, and most small companies already do most of this informally. Writing it down is what turns informal practice into something you can point to if anyone ever asks.

What's worth documenting beyond the policy itself

Keep a simple internal record of who was trained or briefed, when, and on what. This is what satisfies the AI literacy requirement in practice: a record that the training happened, rather than a certificate proving it. A spreadsheet row per session is enough.

"On what" doesn't need to be elaborate. A line like "showed the team how the booking assistant handles customer questions and what it escalates to a person" is a perfectly good entry. The record should reflect what actually happened, not a formal curriculum you didn't run.

If you bring in outside help for this, the advisor retainer includes keeping this kind of documentation current as tools and staff change, so it isn't a one-off exercise that goes stale within a year.

If you haven't done any of this yet, the easiest starting point is a short conversation about what your team is already using and where the gaps are. That's what a free automation plan covers: you describe the business, I tell you what's missing, no obligation either way.

Where this leaves a small company

The bar here is lower than most owners expect, and it is meant to be met by ordinary internal practice, not by hiring a compliance specialist. A one-page policy and a record of who was trained on what covers the requirement as it stands today. This is general information, not legal advice.

Frequently asked questions

Do I need to hire an AI officer to comply with the AI Act?

No. Article 4's AI literacy requirement does not mandate an AI officer or a governance board. An internal record of training or guidance already given to staff is enough, as of the Commission's guidance.

Is there a specific amount of AI training I need to give staff?

No specific training level is mandated, including after the Digital Omnibus on AI amendment to Article 4, which took effect mid-July 2026. The obligation to ensure AI literacy remains, but how you meet it is left to the company.

Does this apply if my company is outside Cyprus?

Yes. I am based in Larnaca, Cyprus, but the AI Act applies across the EU, and Article 4's AI literacy requirement is the same wherever the company is registered.

Behind on AI? Start with a free plan.

A free audit of how you work and a written plan of what to automate. No cost, no commitment. Limited spots.