AI competence and AI compliance are two different things that belong together: AI competence is the ability of people to use AI systems knowledgeably and with awareness of risk. AI compliance is the obligation of a business to comply with the legal requirements when using AI. If you only have one of the two, in the end you don’t really have either under control.
Legal notice: This article is a personal summary of publicly available legal texts, in particular Regulation (EU) 2024/1689. It represents the author’s personal interpretation, makes no claim to completeness, and does not constitute legal advice. Current as of: EUR-Lex. For binding legal assessments, consult a qualified professional.
What is AI competence under the EU AI Act?
Article 4 of Regulation (EU) 2024/1689 requires that employees and you yourself have sufficient AI competence if you use AI in your business. This means the ability to use AI systems knowledgeably and with awareness of risk, to recognise the opportunities, and to assess the risks. This obligation has already applied since February 2025.
How much competence is actually sufficient is not fixed across the board. The law requires that experience, training, role, and context of the respective person be taken into account. A solo entrepreneur who uses ChatGPT for texts needs a different level of knowledge than a company that uses an AI system for automated decision-making.
What is AI compliance?
AI compliance describes something else: whether a company uses the AI tools it deploys in a way that complies with the rules. This is not an individual ability but an organisational task.
One example: a company decides that no customer data or contract content may be entered into public AI tools, because personal data could end up on servers outside the EU. This rule must be documented and known to employees, not just held in the mind of management.
A second example: it is documented which team may use which AI tool for which purpose, for instance marketing for draft texts, but not for the automated evaluation of customer data. This is exactly the difference from competence: compliance regulates the what and how within the business, not the individual person’s understanding.
The four risk classes of the EU AI Act
A central building block of AI compliance is classifying an AI system into the correct risk class, because the specific obligations depend on it. What matters here: it’s not the name of the tool that decides, but the purpose, context, and effect of the specific use.
Prohibited AI practices
Certain AI applications are incompatible with fundamental rights and are therefore banned in the EU. These include, for example, social scoring, certain forms of biometric mass surveillance, or manipulative systems that deliberately exploit people’s vulnerabilities.
High-risk systems
High-risk AI is used in sensitive areas where decisions can have a significant impact on people, for example in recruitment processes, credit lending, personnel decisions, or medical applications. These systems are not banned, but are subject to strict requirements.
Limited risk
For AI systems with limited risk, transparency is the priority. This mainly concerns applications where people interact with an AI or where AI-generated content must be recognisable as such, for example chatbots, synthetic images, or deepfakes. For you, this means: labelling and disclosure obligations under Article 50 may apply.
Minimal risk
Most everyday AI applications fall into this category, for example text assistants, translation tools, spam filters, or spell checkers.
Most solo entrepreneurs, founders, and SMEs operate with everyday AI tools in the minimal to limited risk range. This means manageable, but not zero, obligations.
Transparency obligation under Article 50: what applies from August 2, 2026
The labelling obligation under Article 50 requires that certain AI-generated or AI-supported content be made recognisable as such. It becomes legally binding from August 2, 2026. Since June 10, 2026, the European Commission has already been providing official icons free of charge, so that businesses can prepare ahead of the deadline. For systems already on the market before August 2, 2026, there is an additional transition period until December 2, 2026 for machine-readable labelling.
When does the labelling obligation actually apply?
Article 50 of the EU AI Act regulates several specific transparency obligations. For founders, solo entrepreneurs, and SMEs, three cases are particularly relevant: AI chatbots, deepfakes, and AI-generated text on public affairs.
1. AI chatbots
When someone interacts directly with an AI system, this must generally be recognisable. The disclosure should be made at the latest on first contact and must make clear that the person is not communicating with a human but with an AI. In practice, this means: anyone using a chatbot in customer contact should place the disclosure clearly visibly.
2. Deepfakes
AI-generated or AI-manipulated image, audio, or video content must be labelled as such if it could appear authentic. This applies, for example, to realistic-looking images, videos, or audio recordings that deceptively recreate people, places, or events. A simple notice such as “AI-generated” or “artificially created” is generally sufficient, as long as it is clear and understandable.
3. AI-generated text on public affairs
If a fully AI-generated text on topics such as politics, society, or elections is published, a labelling obligation also applies, provided there was no effective editorial control by a human. It is particularly important here that the text is not just created internally but publicly distributed. Special exceptions apply for journalistic or editorially responsible content.
4. Emotion recognition and biometric categorisation
A further transparency obligation concerns systems for emotion recognition or biometric categorisation. Affected individuals must be informed that such a system is being used. This case is less relevant in everyday practice for many small businesses, but it is still one of the obligatory cases under Art. 50.
How must labelling be done?
Labelling can be done either via an icon or via text. Using the EU icons is voluntary; a clear text notice such as “AI-generated” or “Created with artificial intelligence” is legally just as sufficient. What matters is not the format, but that the labelling is easily understandable and clearly recognisable for users.
Placement is also important: the notice should be visible before or at the latest during the first interaction, remain directly connected to the content, and remain visible even when shared or downloaded. Hidden notices or hard-to-find overlays are not sufficient.
What is not subject to labelling
No labelling is required if the content is obviously artistic, creative, satirical, or fictional. Labelling can also be omitted if an AI text has been substantially revised under genuine human editorial responsibility. The same applies to cases where the use is legally permitted for law enforcement purposes.
A practical example
Elena publishes a blog post on her website about current AI regulation, written entirely by AI, without her own revision. Because this is a text on a matter of public interest published without editorial control, Art. 50(4) applies once the obligation becomes binding from August 2, 2026. She opts for a simple text notice directly below the headline: “This text was created entirely using artificial intelligence.” No icon, no complicated system, one sentence is enough. Effort: two minutes. Whether this achieves full compliance still depends on the overall implementation.
AI competence and GDPR: where they overlap
AI competence doesn’t stop at the boundary of the AI Act. Anyone using AI tools for business purposes should also consider the GDPR, because in practice personal data is often processed. As soon as names, email addresses, customer data, or other personal information are entered into an AI tool, the question arises of whether and under what conditions this is permissible under data protection law.
An important basic principle here: personal data should only be entered into an AI system in anonymised form, or at least only when a clear legal basis and a suitable contract with the provider are in place. This is particularly relevant for tools whose servers are located outside the EU, or where data could be used for training purposes.
In this context, AI competence means recognising in the first place that AI use and data protection are often connected. AI compliance means bindingly defining within the business which data may go into which tool, which may not, and under what conditions this is permitted.
Why a single AI competence course isn’t enough
A common misconception: anyone who has completed an AI competence course thinks the topic is thereby settled. It isn’t.
A course conveys the knowledge an individual needs to assess AI risks, for example bias, hallucinations, risk classes, or handling sensitive data. But it does not replace operational rules. Even if every employee is competent, it remains open which tools are actually approved, which data may be entered, how transparency obligations are implemented in one’s own offering, and who documents the use. These rules do not arise automatically from a course; they must be developed and documented in writing within the business itself.
A course is therefore a necessary but not a sufficient building block. It’s the part an individual can take away for themselves. Operational implementation remains a separate task.
Who is affected?
Anyone who uses AI tools for business purposes is affected, not just corporations with their own legal department. Founders, solo entrepreneurs, and SMEs who use ChatGPT, Claude, or another tool for their work fall under this too.
For a founder who is currently building her business and uses AI daily for texts and research, this mainly means knowing her own limits: what data she enters, how she checks AI results before publishing them. For a solo entrepreneur with their own client base, there’s the added factor that they decide themselves which client data ends up in which tool, here individual competence and entrepreneurial compliance merge in one person. For a small team in an SME, this becomes a shared task: management sets the rules, employees must know and apply them.
The requirements are generally more manageable for smaller businesses than for corporations with high-risk AI systems, but no one is exempt. Anyone who works with ChatGPT daily as a solo entrepreneur doesn’t need an extensive compliance programme, but does need a basic understanding of their own risks and a few clear, ideally written-down rules for themselves.
How are competence and compliance connected?
Both depend on each other. Knowledge without clear rules remains a matter of chance: a competent person, without documented guidelines, still doesn’t know the boundaries of their business and makes their own decision each time, which may differ from the last. Rules without knowledge remain paper: a policy that nobody understands or can apply in everyday life protects no one, it just sits in a drawer or a forgotten folder.
That’s why AI competence and AI compliance cannot be built separately from one another. Only once people understand why a rule exists will it actually be followed in everyday life. And only once rules exist and are documented does individual knowledge become a reliable standard across the whole business, one that can also be demonstrated on request.
Conclusion
AI competence and AI compliance are two sides of the same obligation. One empowers people, the other obligates businesses, and both only work together. Anyone who builds both is not only legally protected but also actually uses AI more safely and effectively in their own business.
Implementation is up to you. This article provides orientation but does not replace individual legal advice.
Sources
This article was created with AI assistance and has been editorially reviewed. It does not constitute legal advice.
This article was created with AI assistance and editorially revised.