Back to blog

AI

AI literacy is already a requirement. How to write an AI policy people actually use

Halvor Hauge
Halvor Hauge·24 September 2026·7 min read
AI literacy is already a requirement. How to write an AI policy people actually use

Most organisations have staff who use ChatGPT, Copilot or Gemini every day. Far fewer have an AI policy that says what is allowed, and fewer still have a training plan. Meanwhile, the EU has made AI literacy a legal duty, and Norway's own AI act is on its way. Below is a checklist for writing AI usage guidelines that people read, understand and follow.

What the AI literacy requirement says

Article 4 of the EU AI Act has applied in the EU since 2 February 2025. It requires organisations that build or use AI systems to make sure the staff who work with those systems know enough to do so responsibly. In its AI literacy Q&A, the European Commission makes clear that this covers a company whose employees use ChatGPT to write ad copy or translate text. Those employees need to know, for example, that the model can make things up. National authorities in the EU supervise and enforce Article 4 from 2 August 2026.

The article was amended this summer. The EU's simplification package for AI (the Digital Omnibus) was adopted as Regulation (EU) 2026/1744 and entered into force on 27 July 2026. The original text required organisations to ensure a sufficient level of AI literacy. The new text says they must take measures to support the development of AI literacy among their staff, and that they are not required to guarantee a specific level for each person. The duty still stands. It is now judged by what you do to build skills. The Commission and member states have also been given responsibility for helping organisations comply, with particular attention to SMEs.

What about Norway? The AI Act is not yet part of Norwegian law, even though Norway is in the EEA. The government put a draft Norwegian AI act out for consultation in 2025, with the Norwegian Communications Authority (Nkom) as the coordinating supervisor. In August 2026, digitalisation minister Karianne Tung announced a new consultation this autumn, adjusted to the EU amendments, with the aim of presenting the bill to parliament in spring 2027. Norwegian groups with a company or office in an EU country will usually be covered there regardless. The same may apply if you offer AI-based services to customers in the EU. If you are unsure, ask a lawyer.

Wherever you stand legally, a good AI policy has to answer the same questions, so there is little to gain from waiting until the law is passed.

The checklist: ten points for an AI policy that gets used

1. Find out what is in use today

Ask employees which AI tools they use, both at work and on personal accounts for work purposes. Do it without anyone getting into trouble. The answers show you where the need is and where the risk sits, and they give you a realistic starting point for the rest of the policy.

2. Clarify your role under the AI Act

The regulation distinguishes between providers, who build AI systems, and deployers, who put them to use. Most organisations are deployers. If you build a chatbot or an AI feature into your own product for customers, you may also be a provider, and the requirements grow. State in the policy which role you have for which systems.

3. List the approved tools

Name the tools and say which account type applies. A free account and a business licence for the same service often come with different terms for storage and model training. Add a simple way to request a new tool, so people have no reason to work around the policy.

4. Classify your information

What employees need most is an answer to "can I paste this in?". Use the classification you already have for information security, if you have one. A common split is public information (free to use), internal information (approved tools only) and personal data, customer data and trade secrets (not without a specific assessment). Give two or three concrete examples in each class.

5. State who owns the output

Whoever uses AI to produce a text, an analysis or a code suggestion is responsible for what gets passed on. Say so plainly. Mention that models can invent sources, figures and quotes, and that anything going to customers or feeding into decisions must be checked by a person.

6. Decide when AI use must be disclosed

Decide when you tell customers, users or applicants that AI has been used. The AI Act's transparency rules (Article 50) apply in the EU from 2 August 2026 and cover chatbots and AI-generated content, among other things. For most organisations a simple rule will do: tell people when they are talking to a machine, and when images or video are generated.

7. Build privacy in from the start

Datatilsynet, the Norwegian Data Protection Authority, tested Microsoft 365 Copilot with NTNU in its regulatory sandbox. The final report from November 2024 recommends, among other things, a data protection impact assessment (DPIA) when generative AI processes personal data, and a rollout in small, controlled steps. It also points out that weak access control in file storage becomes far more visible once an AI assistant can search everything. Logging what employees type into the tool can also clash with Norwegian rules on employee monitoring.

8. Tailor training to the role

The Commission says the measures should take into account what the organisation does, its role, the risk of its systems and the existing knowledge of its staff. A developer, a case handler and a marketer need different training. Start with a shared introduction to how language models work and where they fail, then add role-based sessions.

I have run internal AI literacy sessions for my colleagues at Frontkom myself, using DataCamp as the learning platform. [QA: add your own example from the internal AI sessions at Frontkom, e.g. what worked best]

9. Document what you do

The Commission does not require certificates. It says an internal record of training and other measures is enough. A spreadsheet with date, topic, participants and the policy version in force will do for most organisations. It makes it easy to answer when a customer, auditor or regulator asks.

10. Give the policy an owner and a review date

The tools change every month, and the Norwegian law is not finished. Appoint an owner (ideally together with IT and your data protection officer) and set a fixed review, for example every six months. The next natural checkpoint is when the Norwegian AI act goes out for consultation this autumn.

Common mistakes

  • The policy is too long. A twelve-page document will not be read. Write one page with the essentials and put the details in an appendix.
  • A blanket ban. Bans rarely stop usage. People move it to personal accounts, where you lose all visibility.
  • A copied template. A template from the web gives you structure, but it knows nothing about your systems, data or customers. Points 1 and 4 are work you have to do yourself.
  • One course and done. AI literacy is not a one-off exercise. New tools and new hires mean training has to happen regularly.
  • IT owns it alone. AI in the workplace touches law, privacy, HR and the business itself. If the policy becomes an IT document, it will lack the answers employees need.
  • Ignoring public guidance. Public sector organisations in Norway should read Digdir's guidance on responsible use and development of AI. It is written for the public sector, but much of it works for private companies too.

In Scale & Impact we help organisations with AI advisory and AI training, including writing AI policies and training plans that fit the way they work.

Sources

Transparency note: This article is based on the author's own analysis and experience. AI has been used as an editorial aid for language and structure.