AI governance and AI literacy
A running AI governance program. Policies your organisation adopts, role-differentiated enablement, scenario-based competence evidence, and the assignment rules that put each person on the right path. Built for the EU AI Act literacy and human oversight duties, and structured to support an ISO/IEC 42001 management system.
| Publisher | betteragile GmbH |
| Version | 1.1.0 |
| Released | 2026-07-25 |
| Languages | en, de, es (source en) |
| Review cadence | Every 12 months |
| Evidence validity | 24 months |
What you have to do
- Load it. An administrator uploads the signed program file. The signature is verified and the full contents are shown before anything is created.
- Map the roles. The program describes roles, not your org chart. You map each one to your own departments, activities, plants and lines, and you see the resulting list of who gets what before you commit.
- Approve it. Documents and training land in your review queue and are approved by someone in your organisation who did not author them. Nothing is published in your name until then.
- Audit it. Coverage per role, evidence per person and per version.
See installing a program for the detailed walkthrough.
Before you install
- Required. At least one person who can genuinely stop an AI-supported process. The oversight path assigns real authority. Giving it to someone who cannot reject output, halt a batch or escalate creates the governance gap the program exists to close, and puts their name on it.
- A list of where AI is actually used. It does not have to be complete or formal. Without any list, the role mapping is guesswork and people are assigned depth they do not need while the ones who do go uncovered.
- Works council agreement, where co-determination applies. In Germany and much of DACH, co-determination covers practically any AI touching people, and a rollout without agreement is legally ineffective. This program supplies the training and oversight concept such an agreement normally requires, but it does not replace the agreement.
Who it covers, and what it costs them
Depth follows the role, the risk and the context. Each person sits at one level.
| Level | Who | Time to complete | Per recertification | Evidence |
|---|---|---|---|---|
| A Awareness | Staff without regular operational AI use, and general internal stakeholders. | 25 min | 15 min | Recall only. Proves the person knows the material, not that they would act correctly under pressure. |
| B Responsible user | Administration, knowledge work, communications, HR, sales, project work. | 1 h 15 min | 40 min | The person acts in a realistic situation and is graded against criteria by a reviewer. |
| C Professional operator | Specialist users, analysts, content owners, service staff, operational process owners. | 1 h 40 min | 55 min | The person acts in a realistic situation and is graded against criteria by a reviewer. |
| D Human oversight | Human oversight officers, release approvers, professional control functions, quality assurance. | 2 h | 1 h 10 min | The person acts in a realistic situation and is graded against criteria by a reviewer. |
| E Specialist | Data scientists, developers, data engineers, security specialists, data protection experts, legal and compliance. | 2 h | 1 h 10 min | Assessed by a qualified specialist reviewing the person’s work. |
| F Governance and leadership | Executive management, board, AI governance board, risk owners, chief AI officer, chief data officer, chief information security officer. | 1 h 15 min | 45 min | The person acts in a realistic situation and is graded against criteria by a reviewer. |
What is inside
Policies you adopt
| Item | For | Evidence | Rests on |
|---|---|---|---|
| AI use policy | A, B, C, D, E, F | Read and understood, recorded with an electronic signature. | EU AI Act Art. 4; ISO/IEC 42001 Cl. 7.3; BetrVG §87(1)(6) |
| Human oversight standard | D, E, F | Read and understood, recorded with an electronic signature. | EU AI Act Art. 14; EU AI Act Art. 26 |
| AI use case register | C, D, E, F | Read and understood, recorded with an electronic signature. | EU AI Act Art. 26; ISO/IEC 42001 Cl. 8.1 |
| AI incident procedure | A, B, C, D, E, F | Read and understood, recorded with an electronic signature. | EU AI Act Art. 73; GDPR Art. 33 |
Enablement
| Item | For | Time | Evidence | Rests on |
|---|---|---|---|---|
| Working with AI, the basics | A | 25 min | Recall only. Proves the person knows the material, not that they would act correctly under pressure. | EU AI Act Art. 4 |
| Using AI responsibly at work | B | 1 h | The person acts in a realistic situation and is graded against criteria by a reviewer. | EU AI Act Art. 4; GDPR Art. 5 |
| Exercising human oversight | D | 1 h 30 min | The person acts in a realistic situation and is graded against criteria by a reviewer. | EU AI Act Art. 14; Good practice |
| Running an AI-supported process | C | 1 h 20 min | Recall only. Proves the person knows the material, not that they would act correctly under pressure. | EU AI Act Art. 4; EU AI Act Art. 26 |
| Assessing and controlling AI systems | E | 2 h | Recall only. Proves the person knows the material, not that they would act correctly under pressure. | EU AI Act Art. 6; EU AI Act Art. 25; GDPR Art. 35 |
| Governing AI as a leadership responsibility | F | 50 min | The person acts in a realistic situation and is graded against criteria by a reviewer. | EU AI Act Art. 4; ISO/IEC 42001 Cl. 5.1 |
Assessments
| Item | For | Evidence | Rests on |
|---|---|---|---|
| The confident wrong answer | B | The person acts in a realistic situation and is graded against criteria by a reviewer. | EU AI Act Art. 4 |
| Approve it, we are already late | D | The person acts in a realistic situation and is graded against criteria by a reviewer. | EU AI Act Art. 14 |
| The process that looks perfect | C | The person acts in a realistic situation and is graded against criteria by a reviewer. | EU AI Act Art. 26 |
| Every argument is reasonable | F | The person acts in a realistic situation and is graded against criteria by a reviewer. | EU AI Act Art. 14 |
What people will be able to do
Working with AI, the basics
- Recognise when a system, not a person, produced a result
- Explain why fluent output can be completely wrong
- Name what must never be entered into an unapproved tool
- Say who to contact when a result looks wrong
Using AI responsibly at work
- Decide whether a result is reliable enough for its intended use
- Verify a claim against a source appropriate to that claim
- Recognise when your own checking is not sufficient
- Record a decision so a colleague could follow it
Exercising human oversight
- State what your oversight covers and what it does not
- Read anomaly patterns rather than isolated exceptions
- Name automation bias while it is happening to you
- Use hold and stop authority in a workable way
- Produce a record a later reviewer can reconstruct
Running an AI-supported process
- State the operating envelope of the system you run
- Match the depth of a check to the consequence of the decision
- Read drift as a rate rather than as isolated cases
- Surface a recurring correction as a process defect
- Hand the process over so somebody else can run it correctly
Assessing and controlling AI systems
- Classify by use and consequence rather than by architecture
- Establish what a deployer must know about a bought system
- Design a control that does not rely on operator diligence
- Evaluate a change rather than a model in isolation
- Write an assessment a decision-maker can act on
Governing AI as a leadership responsibility
- State what the organisation answers for regardless of the vendor
- Set a risk appetite specific enough to decide a real case
- Resource oversight so it is genuine rather than nominal
- Read the few indicators that show whether governance works
- Recognise a decision that has quietly arrived at your level
What it addresses
Every item in this program records the instrument it rests on and the date that reading was verified, so a change in the law selects the affected content mechanically.
| Instrument | Referenced | Status |
|---|---|---|
| Regulation (EU) 2024/1689 (Artificial Intelligence Act) | Art. 4 (obligation of effort), Art. 14 (obligation of result), Art. 26 (obligation of result), Art. 73 (obligation of result), Art. 6 (obligation of result), Art. 25 (obligation of result) | in-force, verified 2026-07-25 |
| ISO/IEC 42001:2023 Artificial intelligence management system | Cl. 7.3 (guidance), Cl. 8.1 (guidance), Cl. 5.1 (guidance) | published, verified 2026-07-25 |
| Betriebsverfassungsgesetz §87(1)(6) (Germany, works council co-determination) | general | in-force, verified 2026-07-25 |
| Regulation (EU) 2016/679 (General Data Protection Regulation) | Art. 5 (obligation of result), Art. 33 (obligation of result), Art. 35 (obligation of result) | in-force, verified 2026-07-25 |
What it does not cover
- Classifying your specific systems. The program teaches the classification logic and supplies the pre-check, but the legal determination for a given system is yours to make with current advice.
- Technical conformity work for high-risk systems, such as the risk management system, technical documentation, logging design, conformity assessment and CE marking.
- Data protection compliance. AI rules do not discharge GDPR obligations, and a DPIA where required is separate work.
- The expert review of a specialist's real work product. The specialist path states what that review must establish, but the review itself is performed inside the company on live work and cannot be shipped in a bundle.
- Tool selection and vendor negotiation. The program defines what due diligence must establish, not which vendor to pick.
Release history
1.0.0 (2026-07-25)
- EU AI Act Art. 4, initial. Initial release. Article 4 has applied since 2025-02-02; supervision and enforcement start 2026-08-02.
- Digital Omnibus on AI, loosened. Article 4 became an obligation of effort rather than of result, and high-risk obligations were deferred to 2027-12-02. Content is written to the standard as amended, and the human oversight material is positioned as readiness rather than as an overdue duty.
No recertification required. Existing evidence stays valid.
Initial release, so nothing to recertify.
1.1.0 (2026-07-25)
- EU AI Act Art. 4, clarified. Completes the role model. The professional-operator, specialist and governance-leadership paths are authored, and the AI use case register and incident procedure are added. Article 4 is an obligation of effort discharged with role-differentiated measures, so a program covering half the roles under-delivers on its own reading of it.
- EU AI Act Art. 73, clarified. The incident procedure separates the provider serious-incident duty from the deployer duty to inform without undue delay, and keeps the personal-data breach clock distinct from both.
No recertification required. Existing evidence stays valid.
Additive. No existing artifact changed, so nobody holding valid evidence would now act differently. New roles receive their path for the first time, which is an assignment rather than a recertification.
This program is an organisational instrument and does not constitute legal advice. Classifying a specific AI system, in particular as high-risk, requires current legal review against the applicable text and national implementation.