Skip to main content

AI governance and AI literacy

A running AI governance program. Policies your organisation adopts, role-differentiated enablement, scenario-based competence evidence, and the assignment rules that put each person on the right path. Built for the EU AI Act literacy and human oversight duties, and structured to support an ISO/IEC 42001 management system.

Publisherbetteragile GmbH
Version1.1.0
Released2026-07-25
Languagesen, de, es (source en)
Review cadenceEvery 12 months
Evidence validity24 months

What you have to do

  1. Load it. An administrator uploads the signed program file. The signature is verified and the full contents are shown before anything is created.
  2. Map the roles. The program describes roles, not your org chart. You map each one to your own departments, activities, plants and lines, and you see the resulting list of who gets what before you commit.
  3. Approve it. Documents and training land in your review queue and are approved by someone in your organisation who did not author them. Nothing is published in your name until then.
  4. Audit it. Coverage per role, evidence per person and per version.

See installing a program for the detailed walkthrough.

Before you install

  • Required. At least one person who can genuinely stop an AI-supported process. The oversight path assigns real authority. Giving it to someone who cannot reject output, halt a batch or escalate creates the governance gap the program exists to close, and puts their name on it.
  • A list of where AI is actually used. It does not have to be complete or formal. Without any list, the role mapping is guesswork and people are assigned depth they do not need while the ones who do go uncovered.
  • Works council agreement, where co-determination applies. In Germany and much of DACH, co-determination covers practically any AI touching people, and a rollout without agreement is legally ineffective. This program supplies the training and oversight concept such an agreement normally requires, but it does not replace the agreement.

Who it covers, and what it costs them

Depth follows the role, the risk and the context. Each person sits at one level.

LevelWhoTime to completePer recertificationEvidence
A AwarenessStaff without regular operational AI use, and general internal stakeholders.25 min15 minRecall only. Proves the person knows the material, not that they would act correctly under pressure.
B Responsible userAdministration, knowledge work, communications, HR, sales, project work.1 h 15 min40 minThe person acts in a realistic situation and is graded against criteria by a reviewer.
C Professional operatorSpecialist users, analysts, content owners, service staff, operational process owners.1 h 40 min55 minThe person acts in a realistic situation and is graded against criteria by a reviewer.
D Human oversightHuman oversight officers, release approvers, professional control functions, quality assurance.2 h1 h 10 minThe person acts in a realistic situation and is graded against criteria by a reviewer.
E SpecialistData scientists, developers, data engineers, security specialists, data protection experts, legal and compliance.2 h1 h 10 minAssessed by a qualified specialist reviewing the person’s work.
F Governance and leadershipExecutive management, board, AI governance board, risk owners, chief AI officer, chief data officer, chief information security officer.1 h 15 min45 minThe person acts in a realistic situation and is graded against criteria by a reviewer.

What is inside

Policies you adopt

ItemForEvidenceRests on
AI use policyA, B, C, D, E, FRead and understood, recorded with an electronic signature.EU AI Act Art. 4; ISO/IEC 42001 Cl. 7.3; BetrVG §87(1)(6)
Human oversight standardD, E, FRead and understood, recorded with an electronic signature.EU AI Act Art. 14; EU AI Act Art. 26
AI use case registerC, D, E, FRead and understood, recorded with an electronic signature.EU AI Act Art. 26; ISO/IEC 42001 Cl. 8.1
AI incident procedureA, B, C, D, E, FRead and understood, recorded with an electronic signature.EU AI Act Art. 73; GDPR Art. 33

Enablement

ItemForTimeEvidenceRests on
Working with AI, the basicsA25 minRecall only. Proves the person knows the material, not that they would act correctly under pressure.EU AI Act Art. 4
Using AI responsibly at workB1 hThe person acts in a realistic situation and is graded against criteria by a reviewer.EU AI Act Art. 4; GDPR Art. 5
Exercising human oversightD1 h 30 minThe person acts in a realistic situation and is graded against criteria by a reviewer.EU AI Act Art. 14; Good practice
Running an AI-supported processC1 h 20 minRecall only. Proves the person knows the material, not that they would act correctly under pressure.EU AI Act Art. 4; EU AI Act Art. 26
Assessing and controlling AI systemsE2 hRecall only. Proves the person knows the material, not that they would act correctly under pressure.EU AI Act Art. 6; EU AI Act Art. 25; GDPR Art. 35
Governing AI as a leadership responsibilityF50 minThe person acts in a realistic situation and is graded against criteria by a reviewer.EU AI Act Art. 4; ISO/IEC 42001 Cl. 5.1

Assessments

ItemForEvidenceRests on
The confident wrong answerBThe person acts in a realistic situation and is graded against criteria by a reviewer.EU AI Act Art. 4
Approve it, we are already lateDThe person acts in a realistic situation and is graded against criteria by a reviewer.EU AI Act Art. 14
The process that looks perfectCThe person acts in a realistic situation and is graded against criteria by a reviewer.EU AI Act Art. 26
Every argument is reasonableFThe person acts in a realistic situation and is graded against criteria by a reviewer.EU AI Act Art. 14

What people will be able to do

Working with AI, the basics

  • Recognise when a system, not a person, produced a result
  • Explain why fluent output can be completely wrong
  • Name what must never be entered into an unapproved tool
  • Say who to contact when a result looks wrong

Using AI responsibly at work

  • Decide whether a result is reliable enough for its intended use
  • Verify a claim against a source appropriate to that claim
  • Recognise when your own checking is not sufficient
  • Record a decision so a colleague could follow it

Exercising human oversight

  • State what your oversight covers and what it does not
  • Read anomaly patterns rather than isolated exceptions
  • Name automation bias while it is happening to you
  • Use hold and stop authority in a workable way
  • Produce a record a later reviewer can reconstruct

Running an AI-supported process

  • State the operating envelope of the system you run
  • Match the depth of a check to the consequence of the decision
  • Read drift as a rate rather than as isolated cases
  • Surface a recurring correction as a process defect
  • Hand the process over so somebody else can run it correctly

Assessing and controlling AI systems

  • Classify by use and consequence rather than by architecture
  • Establish what a deployer must know about a bought system
  • Design a control that does not rely on operator diligence
  • Evaluate a change rather than a model in isolation
  • Write an assessment a decision-maker can act on

Governing AI as a leadership responsibility

  • State what the organisation answers for regardless of the vendor
  • Set a risk appetite specific enough to decide a real case
  • Resource oversight so it is genuine rather than nominal
  • Read the few indicators that show whether governance works
  • Recognise a decision that has quietly arrived at your level

What it addresses

Every item in this program records the instrument it rests on and the date that reading was verified, so a change in the law selects the affected content mechanically.

InstrumentReferencedStatus
Regulation (EU) 2024/1689 (Artificial Intelligence Act)Art. 4 (obligation of effort), Art. 14 (obligation of result), Art. 26 (obligation of result), Art. 73 (obligation of result), Art. 6 (obligation of result), Art. 25 (obligation of result)in-force, verified 2026-07-25
ISO/IEC 42001:2023 Artificial intelligence management systemCl. 7.3 (guidance), Cl. 8.1 (guidance), Cl. 5.1 (guidance)published, verified 2026-07-25
Betriebsverfassungsgesetz §87(1)(6) (Germany, works council co-determination)generalin-force, verified 2026-07-25
Regulation (EU) 2016/679 (General Data Protection Regulation)Art. 5 (obligation of result), Art. 33 (obligation of result), Art. 35 (obligation of result)in-force, verified 2026-07-25

What it does not cover

  • Classifying your specific systems. The program teaches the classification logic and supplies the pre-check, but the legal determination for a given system is yours to make with current advice.
  • Technical conformity work for high-risk systems, such as the risk management system, technical documentation, logging design, conformity assessment and CE marking.
  • Data protection compliance. AI rules do not discharge GDPR obligations, and a DPIA where required is separate work.
  • The expert review of a specialist's real work product. The specialist path states what that review must establish, but the review itself is performed inside the company on live work and cannot be shipped in a bundle.
  • Tool selection and vendor negotiation. The program defines what due diligence must establish, not which vendor to pick.

Release history

1.0.0 (2026-07-25)

  • EU AI Act Art. 4, initial. Initial release. Article 4 has applied since 2025-02-02; supervision and enforcement start 2026-08-02.
  • Digital Omnibus on AI, loosened. Article 4 became an obligation of effort rather than of result, and high-risk obligations were deferred to 2027-12-02. Content is written to the standard as amended, and the human oversight material is positioned as readiness rather than as an overdue duty.

No recertification required. Existing evidence stays valid.

Initial release, so nothing to recertify.

1.1.0 (2026-07-25)

  • EU AI Act Art. 4, clarified. Completes the role model. The professional-operator, specialist and governance-leadership paths are authored, and the AI use case register and incident procedure are added. Article 4 is an obligation of effort discharged with role-differentiated measures, so a program covering half the roles under-delivers on its own reading of it.
  • EU AI Act Art. 73, clarified. The incident procedure separates the provider serious-incident duty from the deployer duty to inform without undue delay, and keeps the personal-data breach clock distinct from both.

No recertification required. Existing evidence stays valid.

Additive. No existing artifact changed, so nobody holding valid evidence would now act differently. New roles receive their path for the first time, which is an assignment rather than a recertification.

warning

This program is an organisational instrument and does not constitute legal advice. Classifying a specific AI system, in particular as high-risk, requires current legal review against the applicable text and national implementation.