The EU AI Act

What L&D Teams Need to Know Now

Get AI Knowledge Now

Deadlines | Providers & Deployers |
Risk Categories | AI Literacy | Glossary

EU AI Act at a Glance:

Definition and Implications for L&D

The EU AI Act is the world’s first comprehensive piece of legislation to establish clear rules for the development and use of AI systems. Unlike many other tech regulations, the EU AI Act takes a risk-based approach: the higher the risk an AI system poses to fundamental rights and safety, the stricter the requirements and compliance standards.

The law applies not only to tech giants but to every company in the European Union that offers or uses AI systems—from automated recruitment to AI-powered learning programs. In other words, virtually every company, regardless of size or revenue. For L&D professionals, this means, in concrete terms, that they are responsible for establishing a clear set of rules for the legally compliant use of AI in training and professional development—but at the same time, it also presents a strategic opportunity to establish AI expertise as a competitive advantage within their own organization.

Why the EU AI Act Was Introduced

Background and Objectives

AI is transforming our world of work faster than any other technology before it – however where there are opportunities, there are also risks. The EU AI Act was created to promote innovation while protecting European fundamental values and fundamental rights. The European Union is thus setting a global standard for trustworthy, ethical, and human-centered AI systems.

Here are the three main reasons behind the creation of the EU AI Act:

1. Protection of Fundamental Rights and Security

As AI has become increasingly prevalent in both professional and personal life, concerns have grown regarding data protection, algorithmic discrimination, and the unnoticed manipulation of people.

2. European Competitive Advantage

Europe aims to promote AI systems that inspire trust and acceptance and are characterized by transparency, security, and ethical principles—a distinct European approach to the global AI competition.

3. Harmonization of the Single Market

Instead of a confusing patchwork of national AI regulations, the EU AI Act establishes a uniform legal framework for the entire EU market, which promotes legal certainty for all stakeholders.

Timeline and Implementation Deadlines for Companies

The EU AI Act will not be fully implemented overnight—it will be rolled out in phases to give companies and organizations sufficient time to adapt their processes and systems. L&D teams should definitely keep an eye on this timeline:

Implementation Roadmap for the EU AI Act

July 12, 2024: Official entry into force of the EU AI Act upon publication in the Official Journal of the European Union February 2, 2025: Application of the prohibitions on impermissible AI practices, as well as the obligation to build AI competence (Article 4) and the general principles August 2, 2025: Entry into force of the provisions on notified bodies and governance structures August 2, 2026: Full application of most regulations, including requirements for high-risk AI systems and transparency obligations August 2, 2027: Deadline for compliance with the requirements for general-purpose AI models placed on the market before August 2025 August 2, 2030: Latest date for full compliance of high-risk AI systems used by public authorities

EU AI Act Compliance Timeline for L&D Teams

  • Immediately: Take stock of all AI systems in use in your L&D department and evaluate AI competencies (current vs. target skill levels within the company)
  • Short term (by mid-2025): Risk classification of your AI tools, particularly those used in recruitment, performance evaluation, and learning outcome measurement
  • Medium term (by the end of 2026): Implement robust compliance processes for identified high-risk systems
  • Long term (starting in 2027): Establish continuous monitoring and improvement processes

Provider or Deployer?

Roles and Responsibilities Under the EU AI Act for L&D

The EU AI Act clearly distinguishes between different actors in the AI ecosystem, each with distinct responsibilities. Understand your role so you can take the appropriate compliance measures:

Deployer

Under the EU AI Act, you are considered a deployer if you use AI systems under your own responsibility. Most L&D departments primarily fall into this category when they use off-the-shelf AI solutions for training and talent development.

Typical examples of L&D acting as “operators” of AI systems:

  • They implement an AI-powered Learning Management System (LMS)
  • They use ChatGPT or similar generative AI tools to create, review, or optimize training content
  • They use an AI-powered analytics tool that evaluates the effectiveness and ROI of their training initiatives
  • They use an AI tool that analyzes employee performance reviews and generates data-driven coaching recommendations
  • You use an AI-powered recruiting tool that pre-screens applications or automatically evaluates structured interviews

Operator Obligations Under the EU AI Act:

  • Strict compliance with the AI provider’s usage guidelines and operating instructions
  • Ensuring appropriate human oversight of AI-supported decision-making processes
  • Implementation of systematic logging of usage, particularly for high-risk systems
  • Transparency and disclosure requirements: You must clearly inform individuals when they are interacting with AI (e.g., with AI chatbots) or when their data is being processed by AI (e.g., in automated evaluations)

Download an overview of operator obligations as a PDF (German)

Provider

Under the EU AI Act, you are considered a provider if you develop or place AI systems on the market. This also applies to L&D teams that develop, significantly modify, or repurpose their own AI solutions.

When is an L&D team considered a “provider” under the EU AI Act?

  • You develop an AI-based learning platform that analyzes learning progress and creates personalized learning paths for employees
  • You adapt an existing language model to train a company-specific learning chatbot using proprietary data
  • You program an AI solution that preselects or evaluates applications for your trainee programs
  • You brand an existing AI system with your company name and redistribute it internally or externally
  • You significantly change the intended purpose of an AI system, e.g., from general text analysis to personalized performance evaluation

Provider Obligations Under the EU AI Act:

  • Comprehensive risk assessment and correct classification of your AI systems into risk categories
  • Complete documentation of the entire development process and training data
  • Implementation of quality assurance systems and transparency measures
  • For high-risk systems: Conducting a full conformity assessment in accordance with EU requirements

Download an overview of provider obligations as a PDF (German)

The Four Risk Categories of the EU AI Act

What They Mean for L&D

The risk-based approach of the EU AI Act classifies AI systems into four categories—ranging from prohibited to minimal risk. This classification determines which legal requirements apply to your L&D tools:

Prohibited AI Systems in Learning & Development

Certain AI applications are generally prohibited in the EU, including in the fields of education and training, because they violate fundamental rights or pose unacceptable risks to individuals:

  • AI learning systems that evaluate employees based on their social behavior outside the workplace, thereby limiting career opportunities (“social scoring”)
  • AI tools that use real-time biometric recognition in classrooms or during digital training sessions to monitor participants without their knowledge
  • Learning platforms that use unconscious subliminal techniques to manipulate learners’ behavior or exert psychological pressure
  • Adaptive learning systems that specifically exploit the vulnerabilities of at-risk groups (e.g., older employees, people with learning disabilities) to disadvantage or influence them
  • Gamified learning environments designed to instill addictive behavior or disproportionate performance pressure in people with certain psychological traits

L&D Relevance: Carefully verify that your learning and assessment tools do not contain prohibited techniques such as unconscious manipulation, abusive emotion recognition, or discriminatory social scoring.

High-Risk AI Systems in Human Resources Development

These AI systems must meet strict regulatory requirements, as they can have a significant impact on individuals’ health, safety, or fundamental rights:

  • HR and personnel management tools (e.g., AI systems used for hiring decisions, promotions, or terminations)
  • Education and vocational training applications (e.g., automated assessment of tests or learning outcomes with career implications)
  • AI systems used to select participants for continuing education programs or talent development initiatives, thereby influencing career development opportunities
  • AI applications that automatically assess competencies and use those assessments to determine access to expert knowledge or specializations

L&D Relevance: Many advanced L&D tools that evaluate employees, provide career recommendations, or make decisions about development paths fall into this category, which is subject to comprehensive compliance requirements.

AI Systems with Transparency Requirements in Employee Development

These AI applications must clearly and unambiguously indicate that an interaction with artificial intelligence is taking place or that content has been generated by AI:

  • Chatbots, virtual assistants, and interactive learning guides
  • AI-generated or AI-manipulated content such as text, images, or videos (“deepfakes”)
  • Personalized recommendation systems for learning resources or development paths

L&D Relevance: Your digital learning assistants, AI coaches, and automatically generated learning materials must be clearly labeled as AI-generated or AI-supported for users in order to comply with transparency requirements.

AI with Minimal Risk in L&D Applications

Most simpler AI applications fall into this category and are not subject to any specific obligations under the EU AI Act, but only to general principles:

  • Simple text analysis and classification tools that do not involve decisions affecting individuals
  • Basic AI-powered learning applications such as quizzes or interactive exercises
  • Standard spelling and grammar correction tools in learning platforms
  • Simple, non-personalized content recommendation systems for training materials

L&D Relevance: Even with these systems, which pose minimal regulatory risk, you should pay attention to data protection, fairness, and ethical considerations to implement best practices—even if there are no specific legal requirements.

AI Competence under Article 4 of the EU AI Act:

Key Requirement for L&D

Article 4 of the EU AI Act explicitly emphasizes the fundamental importance of AI literacy for all stakeholders—and this is where Learning & Development teams come into play, as education and training are key to meeting this central requirement.

What Does AI Competence Mean Under the EU AI Act?

AI competence encompasses the structured knowledge, practical skills, and critical understanding needed to:

  • Use AI systems responsibly, safely, and lawfully
  • Understand and communicate the opportunities, risks, and limitations of AI applications
  • Make informed, ethically grounded decisions regarding the use and design of AI
  • Approach AI-generated results and recommendations critically and based on facts
  • Give appropriate consideration to ethical aspects and fundamental rights issues in the use of AI

Which groups of people need to develop AI literacy?

The need to develop and promote AI literacy applies to various target groups within organizations:

  • Executives and decision-makers who make strategic decisions regarding the use of AI
  • Specialists and employees who regularly work with AI systems or use their outputs
  • IT and development teams that implement, customize, or maintain AI systems
  • End users who interact with AI systems or are affected by their decisions
  • Compliance officers and quality managers who must ensure compliance with AI regulations

What are the potential consequences of a lack of AI literacy?

While promoting AI competence under Article 4 of the EU AI Act is a mandatory requirement, in practice it is more of a recommendation. Unlike direct violations of specific technical requirements, no immediate fines are currently provided for in this case. However, this does not mean you should ignore this provision.

The real risk arises in the event of damage: If an inadequately trained employee causes damage through the improper use of an AI system, your company could be accused of violating its general duty of care. In such cases, the lack of evidence of systematic AI training may be viewed as a failure to take appropriate precautionary measures and could result in liability consequences.

Therefore, it is advisable to view AI competency development not merely as a formal requirement, but as an important safeguard against legal and financial risks. In the event of an incident, a documented training program serves as crucial evidence that you have taken your duty of care seriously.

Become EU AI Act-compliant now and equip your team for the future of AI

Article 4 of the EU AI Act requires that your employees have sufficient AI expertise. With our certified training packages—ranging from the 45-minute e-learning course “AI Fundamentals” to personalized coaching for your specific Use Cases—you can ensure your team is legally compliant and ready to meet the AI requirements of the future. Learn more now!

View our AI packages

EU AI Act Glossary

Key Terms Explained Simply

Vendor

A person or organization that develops or markets AI systems. In L&D, you would be considered a provider if your team develops its own AI learning assistant or significantly modifies an existing AI tool.

Operator

A person or organization that uses AI systems in its operations. Most L&D departments are operators when they use off-the-shelf AI tools, such as ChatGPT, to create training materials or AI-powered learning platforms.

GPAI Models (General-Purpose AI)

GPAI models (General Purpose AI) are flexible AI systems capable of performing many different tasks—like a Swiss Army knife among AI programs. While specialized AI can do only one thing (such as sorting photos or translating text), GPAI models can simultaneously generate text, perform calculations, create images, and hold conversations. ChatGPT is a typical example: It can write poetry, help with math problems, and create travel itineraries. The EU AI Act pays particular attention to these versatile AI systems because their broad range of applications means they can have a greater impact. Providers of such all-purpose AI systems must therefore carefully verify that their systems are safe and transparently explain what their AI can and cannot do.

High-Risk AI System

An AI application that poses significant risks to health, safety, or fundamental rights. In the field of learning and development (L&D), this includes AI systems that determine career opportunities, evaluate important exam results, or control access to educational programs.

AI Expertise

The knowledge and skills needed to use AI systems responsibly, understand their capabilities and limitations, and identify risks. The EU AI Act requires companies to foster these competencies among their employees.

AI system

Software developed using machine learning techniques, logic- or knowledge-based approaches, or statistical methods, capable of generating content, predictions, decisions, or recommendations that can influence human behavior.

Simply put: Imagine the difference between two different chefs: An AI system is like a chef who learns from experience, constantly adapts their recipe, and can try something new with every dish. A normal computer program, on the other hand, always follows the exact same recipe without any deviations.

Examples of AI systems:

  • ChatGPT, which can provide different answers to similar questions
  • A program that suggests personalized music recommendations based on your tastes
  • A job application filter that independently decides which candidates to invite for an interview

The following are not AI systems under the EU AI Act:

  • A simple calculator that always gives the exact same answer to “2+2”
  • A navigation system that only uses preprogrammed routes without learning from traffic data
  • A word processor that merely converts the user’s keystrokes without suggesting text
  • A website that always displays the same content and is not personalized

The key difference lies in whether the software can generate content or make decisions on its own that were not precisely preprogrammed, and whether it learns from data and evolves over time.

Human supervision

Ensure that a human always retains control over an AI, understands its decisions, and can intervene when necessary. This oversight must be guaranteed, particularly for high-risk AI.

Prohibited AI Practices

AI applications that are generally not permitted because they are too risky or unethical. These include AI systems designed to manipulate people, conduct comprehensive social assessment, or carry out covert biometric surveillance in public spaces.

Have more questions about the AI Regulation?

Just ask our EU AI Act chatbot and navigate the legal jungle with confidence.

Kreisbild von Jacques Alomo

Jacques Alomo
Head of AI Innovation

Let's set off into the future

Curious about how AI can revolutionize your L&D strategy? Our team of AI experts is ready to help you. Let's chat about your visions, challenges and goals. Get in touch today - let's start your exciting AI journey together!

I would like to start the AI journey

Information as of: April 10, 2025

Note: This information regarding the EU AI Act does not constitute legal advice and is not a substitute for consulting with an attorney specializing in AI law. The content has been compiled to the best of our knowledge and belief, but is not intended to be exhaustive. We recommend consulting with legal experts if you have specific legal questions regarding the EU AI Act and its impact on your L&D processes.

Cookies

Cookies?

In addition to strictly necessary cookies, we also use cookies on our website that help us analyze website traffic, optimize our offers, and personalize your individual user experience. With your consent, data – including your IP address – will be shared with Google and used for advertising measurement and to personalize ads. You can withdraw your consent at any time. For more information, please read our privacy policy: Data privacy