Direct answer
What is automation bias and what should our organisation do about it?
This falls under Article 14: human oversight. That obligation applies from 2 December 2027. There is one exception you have to assess yourself.
This could go the other way
- For remote biometric identification the reinforced requirement of verification by at least two authorised persons applies (Article 14(5)), with the exceptions listed there.
First step: Design and assign effective human oversight.
You describe: Employees blindly trust AI output. You want to know what the AI Act says about this and how to counter it demonstrably. Likely role: deployer (the organisation).
This applies now
- Article 4: AI literacyApplicable
Coming up
- Article 14: human oversightfrom 2 December 2027
- Article 26: obligations of deployers of high-risk AI systemsfrom 2 December 2027
- Annex III: high-risk AIfrom 2 December 2027
- Article 10: data and data governancefrom 2 December 2027
Depends on your situation
- Article 61: informed consent of test subjects for testing in real world conditionsArticle 60(4), point (i), with Article 61(1)
These provisions only apply once the stated fact is established. The locator says which provision settles it.
The AI Act names automation bias explicitly in the context of human oversight of high-risk AI (Article 14): overseers must remain aware of the tendency to automatically rely on AI output. The remedy combines Article 4 measures (training in critical use) and process design: building in moments where a human can deviate with reasons.
Your first actions
- Design and assign effective human oversight. Determine oversight measures per system, appoint competent persons and give them the mandate to intervene or stop.
- Take role- and context-specific AI literacy measures. Determine for each role, system and context which combination of instruction, guidance, practice or training is appropriate.
- Assign human oversight and give those people a mandate. Name, per high-risk system, who exercises oversight, and ensure that person has the competence, training, authority and support to actually set the output aside.
Record this
- Oversight file per system
- AI literacy measures record
- Deployment dossier: logs, worker information and information to affected persons
workplace and staff
AI literacy in recruitment and onboarding at an insurer
Gjensidige Forsikring gives all employees a mandatory e-learning as a baseline and builds role-based depth on top: analysts get model risk and data governance, claims handlers get training on the systems they operate themselves. Where relevant, AI literacy is checked during recruitment and training on AI systems is part of onboarding.
Provenance: This practice was submitted by the organisation itself to the Commission living repository. The repository collects and shares practices; it does not approve them or set them as a standard.
Decide whom you train using the wording the document quotes: Article 4 names your own staff as well as anyone using the systems on your behalf.
Living repository of AI literacy practices, practice submitted by the organisation concerned
workplace and staff
Writing assistant refining completed promotion evaluations
A consultancy firm uses an AI writing assistant to refine managers' promotion reports after evaluations are fully completed. Managers have already recorded the recommendation, justification and ratings; the system improves clarity of language, ensures consistency with corporate style and flags potentially biased wording, after which the manager is required to double-check the revised text.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.
Have the manager fully record the recommendation, justification and ratings first and restrict the system to wording and consistency, and it remains an after-the-fact improvement.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III
workplace and staff
Deviation detection in recruitment that also evaluates the recruiters themselves
An AI system is used in the recruitment of employees. It identifies deviations from previous recruitment decision-making patterns to detect potential inconsistencies with corporate recruitment policies, and in doing so also evaluates the personal characteristics of the recruiters conducting the job interviews. The system runs before recruitment is completed.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.
A system detecting deviations in decision-making can fall under the exemption, but once it also weighs personal characteristics of your own staff there is profiling and that route closes.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III
from another sector: recruitment and selection
Candidate recommendation that automatically becomes a decision
An employer uses a system that ranks applicants and recommends a candidate to hire. In one setup a recruiter weighs that recommendation in their own assessment; in the other the outcome is applied automatically and a candidate is rejected without anyone looking at it.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.
Assess a recruitment system on its intended purpose rather than on whether a recruiter reviews the output, because adding or removing human involvement does not change its high-risk classification.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III
No mandatory course format, no certificate, no exam and no AI officer
The Commission Q&A on AI literacy states that there is no one size fits all when it comes to AI literacy and that no strict requirements or mandatory trainings are imposed. On certification, the Q&A states literally that there is no need for a certificate and that organisations can keep an internal record of trainings or other guiding initiatives. On assessment, it states that Article 4 of the AI Act does not entail an obligation to measure the AI knowledge of employees. On governance, it states that no specific governance structure is mandated to comply with Article 4, so that unlike the data protection officer under the GDPR, no AI officer needs to be appointed. On the level, the Q&A states that following the Digital Omnibus amendment AI literacy remains an obligation for providers and deployers of AI systems, but that no specific or sufficient level is mandated and that the Regulation does not require guaranteeing any specific level of AI literacy of any individual. Against that, the Q&A states that simply relying on the AI systems' instructions for use or asking staff to read them might be ineffective, and that organisations should take into account general AI understanding within the organisation, whether they are a provider or a deployer, the risks associated with the systems deployed, staff knowledge gaps considering technical knowledge, experience, education and training, and contextual factors such as sector, purpose and affected populations. The Q&A further states that organisations may implement different levels of training or learning approaches depending on knowledge, experience, education and role, and that staff with a degree or experience in AI development are normally considered AI literate, while the organisation must still verify that those persons understand the specific AI systems of the organisation, know how to deal with them and are aware of all risks.
Commission Q&A on AI literacy, sections on required level, training formats, certificates, assessment of knowledge and governance structures (consulted 9 August 2026)
Article 4 reaches beyond your own staff, and the national supervisor enforces it
The Commission Q&A on AI literacy states that Article 4 applies to providers and deployers of AI systems and in addition to other persons dealing with the operation and use of AI systems on their behalf, covering persons broadly within the organisational remit, with a contractor, a service provider and a client given as examples. On clients, the Q&A states that they may need AI literacy depending on the specific risk, reasoning that affected persons should understand how decisions taken with the assistance of AI will have an impact on them. On geographic scope, the Q&A states that the AI Act's legal framework applies to both public and private actors inside and outside the EU as long as the AI system is placed on the Union market, used in the Union, or its use has an impact on people located in the EU. On supervision, the Q&A states that the supervision and enforcement of Article 4 is not with the AI Office but under the remit of national market surveillance authorities, and that supervision and enforcement began on 2 August 2026, while Article 4 itself entered into application on 2 February 2025. On sanctions, the Q&A states that national market surveillance authorities could impose penalties and other enforcement measures for infringements of Article 4, that this will be based on national laws that Member States were due to adopt by 2 August 2025, that any sanction must be proportionate and based on the individual case taking into account factors such as the nature and gravity of the infringement and its intentional or negligent character, and that sanctions are more likely if there is proof of an incident due to a lack of appropriate training and guidance. Article 4 is not listed in the enumeration in Article 99(4) of the AI Act, which covers only Articles 16, 22, 23, 24, 26, 31, 33(1), (3) and (4), 34 and 50, so the level of any penalty for Article 4 follows from national law rather than from the Regulation's own ceilings. The Q&A further states that Article 4 reinforces the transparency provisions of Article 13 and the human oversight provisions of Article 14 and indirectly contributes to the protection of affected persons, and that for deployers of high-risk systems the Article 26 obligation to ensure staff are trained to ensure human oversight is a distinct requirement; that requirement becomes applicable on 2 December 2027 for standalone Annex III systems and on 2 August 2028 for Annex I systems.
Commission Q&A on AI literacy, sections on target groups, geographic scope, supervision and enforcement, and sanctions (consulted 9 August 2026)
Article 6 has two separate routes to high-risk
The European Commission's draft guidelines on the classification of high-risk AI of 19 May 2026, which are expressly non-binding, state in paragraph (7) that an AI system is high-risk in two scenarios: first, where it is intended to be used as a safety component of a product, or is itself a product, covered by the Union harmonisation legislation listed in Annex I and required to undergo third-party conformity assessment; and second, where it falls within one of the use cases in the areas listed in Annex III. Paragraph (448) of those same draft guidelines notes that the Article 113 application dates have been postponed by the AI Omnibus to 2 December 2027 for the Article 6(2) route and 2 August 2028 for the Article 6(1) route.
Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II, paragraph (7); section V, paragraph (448)
Broadly positioned and general purpose AI systems: a disclaimer is not enough
According to the non-binding draft guidelines of 19 May 2026 on the classification of high-risk AI, paragraph (12) provides that where the instructions for use, contractual arrangements, terms of service, usage policy, promotional and sales materials or technical documentation present the AI system as broadly applicable across a generality of contexts and functions, and do not consistently limit its application or exclude high-risk uses, the system's intended purpose will be deemed to also encompass high-risk use cases and therefore qualify as high-risk. Under these draft guidelines this applies in particular where such uses are feasible and reasonably foreseeable given the system's functionalities and capabilities. The same paragraph states that merely asserting, for example in the terms of service, that high-risk uses are excluded is insufficient where the provider's overall presentation, examples or product positioning effectively provides for or promotes such uses, and that any limitations of use must be described clearly, concretely and coherently across all materials.
Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.2, paragraph (12)
prEN 18229-3: AI trustworthiness framework part 3, transparency and human oversight
prEN 18229-3 (AI trustworthiness framework, Part 3: Transparency and human oversight) is the JTC 21 deliverable under M/613 addressing Articles 13 and 14 of the AI Act: transparency and provision of information to deployers, and the design for effective human oversight of high-risk AI systems. As at June 2026 the deliverable was at the drafting stage. It has not yet been published as an EN and is not cited in the Official Journal. This deliverable concerns Article 14 (high-risk) and not the Article 50 transparency obligations, which apply since 2 August 2026.
ISO/IEC 5259 series: data quality for analytics and machine learning
The ISO/IEC 5259 series (Artificial intelligence: Data quality for analytics and machine learning) comprises five parts: part 1 (overview, terminology and examples), part 2 (data quality measures), part 3 (data quality management requirements and guidelines) and part 4 (data quality process framework), all published in 2024, plus part 5 (data quality governance framework), published in February 2025. CEN-CENELEC has adopted parts as European standards, including EN ISO/IEC 5259-4:2025 and EN ISO/IEC 5259-3:2025. No part is cited in the Official Journal, so no presumption of conformity under Article 40 arises. The deliverable intended to do so for Article 10 is prEN 18284.
prEN 18284: quality and governance of datasets in AI
prEN 18284 (Artificial intelligence: Quality and governance of datasets in AI) is the JTC 21 deliverable under M/613 for Article 10 of the AI Act, which sets requirements for the training, validation and testing datasets of high-risk AI systems. As at June 2026 the deliverable was at the drafting stage. It has not yet been published as an EN and is not cited in the Official Journal.
General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.
Full map for your situation