Compliance · EU AI Act

EU AI Act records for companies that use AI

Most SMBs are deployers under the EU AI Act: they use AI tools rather than build them. A duty that already applies to them is AI literacy (Article 4), in force since 2 February 2025. VAHTOR keeps the evidence in one place: AI tool inventory, policy acceptance, literacy course and quiz records, and an audit trail.

What the EU AI Act asks of companies that use AI

Obligations depend on your role and on each system's risk level. A company that uses tools like ChatGPT or Copilot at work is a deployer. AI literacy measures (Article 4) and the ban on prohibited practices (Article 5) have applied since 2 February 2025. Heavier duties apply mainly to high-risk uses, such as AI in recruitment or credit decisions.

  • Deployer, not provider, for most SMBs
  • Article 4 AI literacy applies to every deployer
  • High-risk duties depend on the use case

AI literacy (Article 4): training with records

VAHTOR includes a workspace AI literacy course with modules and a quiz. You set the pass mark once, and completions are recorded per person. The law does not prescribe a specific course or certificate; records of the measures you took are what you can show when asked.

  • One course for the whole company
  • You set the pass mark
  • Completion is on the record

Know which AI tools are in use

AI Act work starts with an inventory. The extension brings the AI tools people actually use into one registry, where you approve, restrict or block them.

  • Live inventory of AI tools in the browser
  • Approve, restrict or block company-wide
  • Changes logged in the audit trail

A policy people accept, and an audit trail

Publish a company AI policy from a template, track acceptance by version and keep a record of publishes, tool decisions and settings changes, without storing anyone's chats.

  • Policy acceptance tracked by version
  • Audit trail of governance actions
  • Evidence without chat content

High-risk flagging and basic reporting

Flag tools or uses that may fall into a high-risk category for review, and export basic EU AI Act reporting. VAHTOR supports your process; classification decisions and legal advice stay with you and your advisers.

  • Human decisions on tool status
  • Risk flags for review
  • Not legal advice

Frequently asked questions

Does the EU AI Act apply to small companies that only use ChatGPT?

Yes, in a limited way. A company that uses AI tools at work is a deployer. Deployers must take AI literacy measures for staff (Article 4) and avoid prohibited practices (Article 5). Heavier obligations apply if you use AI in high-risk areas listed in Annex III, such as hiring. This is not legal advice.

What is the Article 4 AI literacy requirement?

Providers and deployers must take measures to support the AI literacy of their staff and others using AI on their behalf, taking into account their knowledge, experience and the context of use. It has applied since 2 February 2025; Regulation (EU) 2026/1744 (the Digital Omnibus, in force 27 July 2026) reworded it and made clear that no specific literacy level has to be guaranteed. No specific course or certificate is prescribed, so keep records of what you did.

Is there a deadline for AI literacy training?

There is no separate training deadline. The duty has applied since 2 February 2025 and is ongoing: train new staff and refresh the training when your AI tools change.

Does VAHTOR make us EU AI Act compliant?

No tool can do that on its own. VAHTOR gives you evidence (inventory, policy acceptance, literacy records and an audit trail) that supports your compliance work. It is not legal advice.

Which VAHTOR plan includes AI literacy tracking?

Employee AI literacy training tracking and high-risk flagging are in Business and Enterprise. Starter includes the AI tool inventory, AI policy setup, policy acceptance tracking, EU AI Act basic reporting and an audit trail.

Who supervises the EU AI Act in Finland?

Supervision is split between several authorities. Traficom acts as the national contact point and supervises transparency obligations, while sector authorities such as Tukes, the Financial Supervisory Authority and the Data Protection Ombudsman cover their own areas.

Build your AI Act evidence base

Create a workspace and start documenting inventory, policy and training.

Get started