# The EU AI Act and AI literacy at work

*What the Act asks after the 2026 changes, how the UK differs, and the working habits that make AI safe to use.*

## Production summary

- Modules to record: 2
- Total script: 973 words, about 6 minutes of finished audio
- Voices: Emma (host) and George (practice educator)
- Level: Any member of staff who uses AI tools, and the managers responsible for them

## Accreditation wording that must appear in the description

- **The CPD Certification Service** (planned): Application scheduled.
- **Regulation (EU) 2024/1689 (the AI Act) as amended by Regulation (EU) 2026/1744** (aligned): Written against the Act as amended in July 2026. Our own summary, which is not legal advice and carries no endorsement from any EU body.
- **UK GDPR and the Data (Use and Access) Act 2025** (aligned): The UK material is written against the legislation as in force in October 2026. Our own summary, with no endorsement from the regulator implied.

> Do not upgrade any of these words in a description or a thumbnail. Aligned is not accredited, and planned is not approved.


---

## The AI Act after the 2026 changes: risk levels, dates and who it reaches

**Runtime** about 4 minutes. **Words** 542. **Starts at** 00:00 in the full course recording.

### Learning outcomes to state on camera

- Describe the four levels of risk with an example of each
- State the dates that apply after the July 2026 amendment
- Explain what Article 4 now asks on AI literacy
- Explain the transparency rules in Article 50
- Say when the Act reaches a UK organisation, and how the UK differs

### Script


`[CUE 1]` *A pyramid of four levels: banned, high risk, limited risk and minimal risk, each with an example*

**EMMA**  [00:00]
George, the EU AI Act. I've sat through two webinars on it and they gave me different dates. Which is right?

**GEORGE**  [00:08]
Possibly neither, if they were recorded before July 2026. The Act was amended that month. So let me give you the shape first and the dates second.

**EMMA**  [00:19]
Go on.

**GEORGE**  [00:20]
The Act doesn't treat AI as one thing. It asks what the system is used for and sorts it into four levels. Banned. High risk. Limited risk. And minimal risk, which is most everyday use.

**EMMA**  [00:34]
What's banned?


`[CUE 2]` *A timeline from August 2024 with the amended dates of December 2027 and August 2028 replacing a crossed out August 2026*

**GEORGE**  [00:34]
Things like social scoring, harmful manipulation, and emotion recognition of staff at work or pupils at school, unless it's for medical or safety reasons.

**EMMA**  [00:44]
And high risk?

**GEORGE**  [00:45]
Allowed, with heavy duties. Recruitment and managing workers. Education and exams. Access to essential services and credit. And AI that's a safety component of a regulated product, like a machine.

**EMMA**  [00:57]
So a tool that ranks job applicants.

**GEORGE**  [01:00]
High risk. Whereas a customer service chatbot is limited risk. You just have to tell people it's AI. And a grammar assistant is minimal.


`[CUE 3]` *Article 4 before and after: ensure a sufficient level, replaced by take measures to support*

**EMMA**  [01:10]
Now the dates.

**GEORGE**  [01:11]
In force 1 August 2024. Bans and the AI literacy duty since 2 February 2025. Then the amendment. Regulation 2026/1744, published 24 July 2026, in force 27 July. It moved the main high risk duties from August 2026 to 2 December 2027 for stand-alone systems, and 2 August 2028 for AI built into regulated products.

**EMMA**  [01:33]
So anyone telling me high risk started this August is out of date.

**GEORGE**  [01:38]
Yes. Check the date on whatever you're relying on. What did keep its date is transparency. That applied from 2 August 2026.

**EMMA**  [01:47]
Meaning?


`[CUE 4]` *A chatbot, a realistic generated image and a block of generated text each carrying a visible AI label*

**GEORGE**  [01:47]
Article 50. Tell people when they're interacting with an AI system unless it's obvious. Disclose content generated or manipulated to look real. And providers must mark generated text, images, audio and video so it can be detected.

**EMMA**  [02:02]
And the training duty? I heard that was dropped.

**GEORGE**  [02:06]
Reworded, not dropped. Article 4 used to say ensure a sufficient level of AI literacy. Now providers and deployers must take measures to support the AI literacy of their staff. Nobody has to guarantee a level for an individual. Training and a record of it is the obvious measure.

**EMMA**  [02:25]
We're in the UK. Does any of this bind us?

**GEORGE**  [02:29]
It isn't UK law. It reaches you if you place an AI system on the EU market, or if the output of your system is used in the EU. And the fines are large. Up to 35 million euros or 7 per cent of worldwide turnover for banned practices.


`[CUE 5]` *The EU and the UK side by side: one Act with fines, and existing regulators with four safeguards for automated decisions*

**EMMA**  [02:49]
And if we've no EU link at all?

**GEORGE**  [02:52]
Then UK law applies, and the UK has no single AI statute. Existing regulators apply existing law, guided by five principles. Data protection does most of the work.

**EMMA**  [03:03]
Anything new there?

**GEORGE**  [03:04]
Yes. Since 5 February 2026 the rules on solely automated decisions changed. A decision with legal or similarly significant effect can be made by automated means only with safeguards. The person is told, can make representations, can get a human to intervene, and can contest it.

**EMMA**  [03:23]
So either way a person can ask for a human.

**GEORGE**  [03:27]
Either way. And either way, the system decided is not a defence. The organisation using the tool answers for what it does with it.

### Sources for the on screen credit

- Regulation (EU) 2024/1689 (Artificial Intelligence Act), Articles 2, 4, 5, 6, 50 and 99, EUR-Lex
- EU Digital Omnibus on AI enters into force (Regulation (EU) 2026/1744), Hunton Andrews Kurth
- EU AI Act Omnibus agreement: postponed high risk deadlines and other key changes, Gibson Dunn
- Data (Use and Access) Act 2025, legislation.gov.uk
- A pro-innovation approach to AI regulation, GOV.UK

---

## Five habits for using AI at work

**Runtime** about 3 minutes. **Words** 431. **Starts at** 03:36 in the full course recording.

### Learning outcomes to state on camera

- Explain why a fluent answer is not evidence of a correct one
- Decide what may and may not be put into an AI tool
- Check AI output in proportion to what depends on it
- Say when and how to tell people that AI was used
- Recognise unapproved AI use and respond to it

### Script


`[CUE 1]` *A confident paragraph with one invented reference highlighted, and a tired reader skimming past it*

**EMMA**  [03:36]
George, the law's one thing. But what should I actually do differently on Monday?

**GEORGE**  [03:42]
Five habits. And they don't depend on which country's law you're under. First, know what the tool is doing. A generative tool produces the most plausible next words. It isn't looking facts up unless it's been connected to a source.

**EMMA**  [03:58]
Which is why it invents references.

**GEORGE**  [04:00]
Yes. It sounds as confident when it's wrong as when it's right. And we make it worse, because people trust automated suggestions more than they deserve. Automation bias. The better the tool, the less we look.


`[CUE 2]` *Three kinds of information stopped at a gate marked approved tools only: personal, confidential, commercially sensitive*

**EMMA**  [04:15]
Habit two?

**GEORGE**  [04:15]
Think before you paste. What you type goes somewhere. With an approved tool there's a contract saying what the supplier may do with it. With a tool you chose yourself, there isn't.

**EMMA**  [04:28]
So what stays out?

**GEORGE**  [04:30]
Personal data. Anything confidential to a customer or client. Anything commercially sensitive. Those go only into tools your organisation has approved for that purpose.


`[CUE 3]` *A ladder of checking from read it, to verify against the source, to check against an authority, to a human decides*

**EMMA**  [04:39]
If I take the names out?

**GEORGE**  [04:42]
Not enough. Job title, location, dates and unusual details can identify someone on their own. My test is this. If you wouldn't email it to a stranger, don't paste it.

**EMMA**  [04:54]
Three.

**GEORGE**  [04:54]
Check in proportion. An internal first draft needs a read. A figure going to a customer needs verifying against its source. And anything about the law, a medicine, a safety limit or a person needs checking against something authoritative. Every time.


`[CUE 4]` *A chatbot, a generated image and a drafted letter each with a plain label saying AI was used*

**EMMA**  [05:11]
And decisions about people?

**GEORGE**  [05:12]
A human makes the decision and can explain it. Who's interviewed, who gets credit, who's disciplined. That's where the EU's high risk category and the UK's automated decision rules both bite.

**EMMA**  [05:25]
Four.

**GEORGE**  [05:25]
Be open about it. If a customer's talking to an AI system, they should know. If something's been generated or altered in a way that could mislead, say so. And if someone would feel misled to learn later that AI wrote it, tell them now.


`[CUE 5]` *A member of staff telling a manager at once, with a 72 hour clock and a list of approved tools*

**EMMA**  [05:43]
Am I still responsible for it?

**GEORGE**  [05:46]
Completely. Whatever produced the first draft, it's your work.

**EMMA**  [05:49]
And five.

**GEORGE**  [05:50]
Speak up. Unapproved use at work, people call it shadow AI, is usually someone trying to get through their workload. If you've shared something you shouldn't have, tell your manager or data protection lead straight away.

**EMMA**  [06:04]
Why the hurry?

**GEORGE**  [06:06]
A reportable breach has a 72 hour deadline, and it runs from when the organisation becomes aware. Every hour you wait comes off theirs.

**EMMA**  [06:15]
And one thing to do today?

**GEORGE**  [06:18]
Ask your manager for the list of approved AI tools and what each may be used for. If there isn't a list, that's the first thing to fix.

### Sources for the on screen credit

- Regulation (EU) 2024/1689 (Artificial Intelligence Act), Articles 4, 14, 26 and 50, EUR-Lex
- Guidance on AI and data protection, Information Commissioner's Office
- Data (Use and Access) Act 2025, legislation.gov.uk
- Personal data breaches: a guide, Information Commissioner's Office

---

*Copyright WAJD Group. Built by WAJD AI.*