ยท 6 min readยทen

    AI Act Regulator Interview Preparation: What Your Team Needs to Know

    When a national AI authority sends inspectors, they don't just talk to the CEO. Your frontline employees will face questions too. Here is exactly how to prepare your team without coaching them into giving scripted answers.

    The inspector will ask your employees, not your lawyer

    AI Act regulator interview preparation is not a management exercise. Under Article 99 of the EU AI Act, national market surveillance authorities have broad powers to conduct on-site inspections, request documentation, and interview staff directly. That means the person who runs your CV-screening tool, approves loan applications with an AI assist, or schedules shifts using an algorithmic system may find themselves answering questions from an inspector without a compliance officer in the room.

    This is not hypothetical. The Dutch Autoriteit Persoonsgegevens (AP) has already signalled that AI oversight is a priority area. The Belgian APD/GBA has issued guidance connecting AVG/GDPR accountability obligations to AI deployment practices. Inspectors are trained to spot the gap between polished management presentations and what employees actually do day-to-day.

    The good news: you do not need to turn your team into compliance experts. You need to make sure they understand what they use, why it matters, and where to find the right paperwork when asked.

    What inspectors actually ask employees

    Inspectors tend to ask three types of questions to frontline staff.

    First, operational questions. These establish what the employee actually does with the AI system:

    • "Can you walk me through a typical decision where this tool is involved?"

    • "What does the output look like, and what do you do with it?"

    • "Have you ever overridden the system's recommendation? What happened next?"

    Second, awareness questions. These test whether the employee has received meaningful training under Article 4 of the EU AI Act, which requires deployers to ensure staff have sufficient AI literacy:

    • "Do you know what kind of AI system this is?"

    • "Were you trained on how to use this tool?"

    • "Do you know what to do if the system makes a mistake?"

    Third, documentation questions. These check whether your Article 26 obligations as a deployer are actually implemented in practice:

    • "Is there a policy or manual for this tool? Where would you find it?"

    • "Do you know who in your organisation is responsible for this AI system?"

    • "Have you ever reported a problem or near-miss with this tool?"

    None of these questions require legal knowledge. They require operational clarity.

    Role-by-role: what each person needs to know

    Different employees face different questions. Here is a practical breakdown.

    HR and Recruitment staff

    If your team uses AI-assisted CV screening or psychometric assessment tools, inspectors will focus on whether human review is genuinely happening. Article 26 requires deployers of high-risk systems to ensure human oversight. Your HR staff should be able to explain:

    • Whether every rejected candidate was reviewed by a human before a final decision

    • Where the instructions for using the tool are stored

    • Who to contact if the tool produces an unexpected or unfair-looking result

    They do not need to cite articles. They need to know the three points above.

    Line managers and operations staff

    Managers who use AI tools for scheduling, performance scoring, or resource allocation should be able to describe the decision flow simply. The inspector's core interest is whether the AI output is treated as a suggestion or as a final ruling. Staff should be able to say, in plain words, how much weight they give the system and what they do when they disagree with it.

    Finance and credit teams

    If your organisation uses AI in lending or financial risk assessment, this sits in high-risk territory under Annex III of the EU AI Act. Finance staff should know the name of the system they use, whether it is provided by a third party, and where the provider's documentation lives. Inspectors may ask whether staff have seen the technical documentation required under Article 11.

    IT and system administrators

    These employees may be asked about logging and monitoring. Article 26 requires deployers to keep logs where technically possible. Your IT team should know whether logs are being generated, how long they are retained, and who has access to them.

    How to prepare staff without scripting their answers

    This is the tension every compliance officer faces. You want prepared employees, not robotic ones. Inspectors are experienced at spotting rehearsed answers and will probe harder when they detect them.

    The approach that works is awareness training anchored to real workflows, not abstract compliance briefings.

    Run short sessions, 30 to 45 minutes maximum, where you walk each team through the actual tools they use and three things only: what the tool does, what their role is in checking its output, and where to find the relevant policy document. Keep records of who attended and when. Those attendance records are themselves evidence of compliance with Article 4.

    Avoid drilling employees with mock Q&A sessions where you supply the correct answer. Instead, ask open questions: "Tell me how you use this tool on a Monday morning." If the answer is muddled, that is a signal your process needs clarifying, not that the employee needs a better script.

    Do brief your staff on one procedural right: they can ask an inspector to pause and consult your designated AI compliance contact before answering technical questions. This is not obstruction. It is reasonable practice and inspectors expect it.

    The documents employees should be able to reference

    Your team does not need to memorise documentation. They need to know where it lives.

    Every employee who regularly uses a high-risk AI system should be able to point to:

    1. The tool policy or user guidance โ€” a plain-language document explaining what the tool does and the rules for using it. This should live somewhere obvious: an intranet page, a shared folder, a named section of your employee handbook.

    2. The incident or anomaly reporting process โ€” a simple form or named contact for raising concerns. Inspectors will ask whether this exists. If your employee says "I'd just email my manager," that is not sufficient documented process.

    3. Training completion records โ€” employees should know that their training attendance is logged and, if asked, who holds those records. Your HR or compliance function should maintain these centrally.

    4. The name and contact of your AI system owner โ€” every deployed AI system should have a designated responsible person internally. Staff should know who that is.

    These four items are not complex. They do require deliberate setup. Many SMEs we speak with have done the thinking but not the filing. The inspector cannot see thinking.

    One week before an inspection: a practical checklist

    If you receive notice of an inspection (Article 99 allows for both announced and unannounced visits, though announced visits give you time to prepare), run through these steps:

    • Verify that your AI system inventory is current and accessible

    • Confirm that every system in scope has a named owner

    • Check that training records cover all staff who use each system

    • Distribute a one-page "what to expect" note to relevant employees โ€” not a script, a context note explaining that an inspector may ask them about their daily work with AI tools

    • Remind staff of their right to consult your compliance contact before answering technical questions

    • Ensure your incident log is up to date, even if it shows zero incidents

    A zero-incident log is not a warning sign. It becomes one only if your process for reporting incidents does not exist or cannot be demonstrated.

    Start with a clear picture of what you are deploying

    You cannot prepare your team to answer questions about systems they do not know they are using. The single most effective step any SME can take right now is to complete an AI system inventory and confirm which systems fall under high-risk categories in Annex III.

    From that inventory, everything else follows: ownership, documentation, training, and the quiet confidence your employees will need if an inspector ever walks through the door.

    Run a free 2-minute compliance check at comply.khairos.ai to see where your organisation stands today and which preparation steps are most urgent for your sector.

    References

    1. Article 99 of the EU AI Act

    2. Article 4 of the EU AI Act

    3. Article 26

    4. Annex III of the EU AI Act

    5. comply.khairos.ai

    Sources

    1. Article 99 of the EU AI Act
    2. Article 4 of the EU AI Act
    3. Article 26
    4. Annex III of the EU AI Act
    5. comply.khairos.ai

    Klaar voor jouw AI-traject?

    Plan een vrijblijvende kennismaking - in 30 minuten weten we waar AI voor jouw bedrijf de moeite waard is.

    Plan een kennismaking