AcademyAI

How do I document AI training for the regulator?

What belongs in an AI competence evidence file, which records the regulation actually requires, how long to keep them and who asks for them in Germany. Including a template for the four mandatory entries.

By Florian Obermeier · Marketing Operations Manager
How do I document AI training for the regulator?

Record four entries per person: which AI systems they use in their daily work, which training measure they completed and when, which topics that measure covered, and how participation is reliably evidenced. Together these four establish the link between what was taught and what is actually deployed, which is exactly what matters since the Digital Omnibus. A stack of attendance sheets without role mapping does not establish it.

What you’ll take away:

  • The AI Regulation prescribes neither a specific certificate nor a specific training format. It requires traceable measures.
  • The evidence stands or falls with the mapping of person to deployed system. Without that mapping, even a high-quality certificate is worth little.
  • Article 4 carries no penalty provision of its own. The documentation still gets requested, because other obligations build on it.
  • The regulation states no explicit retention period for Article 4 records. In practice, the lifetime of the deployed system plus a buffer works well.
  • Since 2 August 2026 the Bundesnetzagentur is the central AI supervisory authority in Germany.

How do I document AI training for the regulator?

Keep a list in which every person appears with the AI systems they use, the training measure they completed including the date, the topics covered and a participation record. Add a short note on why those topics fit those systems. That makes the obligation under Article 4 of the AI Regulation traceable.

The regulation prescribes no particular form. A table in your quality management system, a section in your HR system or a properly kept folder all serve the purpose. What it has to achieve: a third party should be able to see, without asking questions, who works with what and what that person has learned about it.

In practice, documentation rarely fails because of filing. It fails because nobody has written down which AI tools are in use in the business at all. Without that inventory there is no reference point against which any training could be evidenced.

What evidence do I need for AI compliance?

For the competence obligation under Article 4, records of the measures carried out and their link to the deployment context are enough. For higher-risk systems and for the transparency obligations under Article 50, further documents are added, for example on labelling outbound content and on human oversight.

For an SME deploying AI and running no high-risk systems, the realistic package has four parts. First, the inventory of deployed AI systems with purpose and affected roles. Second, the mapping of which person works with which system. Third, the training records per person. Fourth, a short written rule on what is permitted with AI in the business and what is not.

The fourth part is the one most often forgotten and the cheapest. A one-page policy naming tool approval, data boundaries and labelling duties is written in an afternoon and answers most follow-up questions before they are asked.

Do I have to document AI competence training at all?

The regulation states no explicit documentation duty for Article 4. It requires measures to promote AI literacy, and anyone who owes measures must be able to evidence them if challenged. Without records there is no evidence.

The Digital Omnibus, in force since 27 July 2026, adjusted Article 4 from “ensure” to “promote”. That lowers the requirement on the outcome, not on the process. Nobody has to guarantee a particular competence level. That something was done, and that it fit the actual deployment, remains the core statement to be evidenced.

There is a practical reason too. Tenders, cyber insurance questionnaires and supplier assessments now regularly ask about AI competence. If you have the file, you answer in five minutes.

Who asks for the evidence in Germany?

Since 2 August 2026 the Bundesnetzagentur has been the central AI supervisory authority in Germany. Alongside it, the sector authorities remain relevant, for example the data protection supervisory authorities where personal data is involved and market surveillance for products containing AI.

For a company with 50 to 500 employees using language models in day-to-day office work, an unprompted audit is currently unlikely. Three other routes are more realistic: a complaint, an incident with external visibility, or a business partner requesting the documents as part of their own due diligence.

That does not change the recommendation. A file that exists costs half a day once. A file that does not exist when it is needed costs weeks.

Is a certificate of attendance enough?

On its own, no. A certificate evidences that someone completed a measure. It does not evidence that the content matched the systems that person actually works with. Only the role mapping establishes that link.

This is why the order inside the file matters. First the system inventory, then the mapping of people, then the records. Starting with the certificates produces a stack that leaves the decisive question open.

A certificate with an assessment is still considerably stronger than a pure attendance list, because it documents a verified completion rather than mere presence. The PASSION4IT Academy issues an archivable certificate per completed module, which automates the fourth building block of the file.

How long do I have to keep the records?

The AI Regulation names no explicit retention period for Article 4 measures. A workable benchmark is to keep the records for as long as the associated AI system is in use, and then for a few more years in line with your usual retention practice for compliance documents.

More important than the duration is the review date. Tools and the legal position change quickly, most recently through the Digital Omnibus in July 2026 and the applicability of Article 50 since 2 August 2026. A file from 2025 that nobody has touched since says little about today’s deployment.

Set a fixed annual date to check three things: is the system list still current, are new employees mapped, has anything changed in the legal position.

What does the evidence file look like in practice?

Four documents, and as a rule nothing more.

DocumentContentEffort first time round
System inventoryWhich AI tools are approved, for what, who may use them2 to 3 hours
Role mappingPerson, role, systems used, risk classification1 to 2 hours
Training recordsDate, topics, format, completion record per personruns alongside the training
AI policyApproval, data boundaries, labelling, point of contact2 hours

The time estimates assume a manageable tool landscape. If the system inventory runs longer than one page, that is a finding in itself and usually points to shadow AI that has grown over time.

The effort is one-off. After that it is maintenance, and that attaches to existing processes such as onboarding new employees.

Frequently asked questions (FAQ)

Does every person need their own certificate? No. What is required is a traceable measure per person. A certificate is the most convenient record; a documented internal briefing with an assessment serves the same purpose.

Does this apply if we only use ChatGPT in the office? Yes. The competence obligation attaches to the deployment of AI systems, not to their risk class. The scope of the measure does follow the risk, so for general office use it turns out correspondingly lean.

What happens if the documentation is missing? Article 4 carries no penalty provision of its own. The risk sits in civil liability after an incident and in the obligations that build on competence, in particular the labelling duty under Article 50, which has carried penalties since 2 August 2026.

Is a spreadsheet enough? Yes, if it contains the four entries and is maintained. The regulation prescribes no system. A tool nobody maintains is worse than a spreadsheet somebody does.

Do managers have to be trained as well? Yes, and they sensibly come first. Without a decision on which tools are approved, no suitable measure can be tailored for the remaining roles.

Further reading

Want the evidence file set up cleanly once and only maintained afterwards? Book a conversation.

Sources: AI Regulation Art. 4 and Art. 50 · Regulation (EU) 2026/1744 (Digital Omnibus Regulation on AI), in force since 27 July 2026 · European Commission, AI literacy questions and answers (digital-strategy.ec.europa.eu) · Bundesnetzagentur as central AI supervisory authority since 2 August 2026 · PASSION4IT Academy, as of August 2026. Practical guidance, not legal advice. As of 18 August 2026.