What Is AI Attestation and Why Your Team Needs It?

Photo: Tima Miroshnichenko / Pexels
Key takeaways
- AI attestation is the record that proves each employee has read, understood and accepted your AI usage policy - not just that a policy exists.
- It's the most direct way to evidence the EU AI Act's Article 4 AI-literacy duty, in force since 2 February 2025.
- SOC 2 auditors and enterprise security questionnaires increasingly ask for attestation records, not just a copy of the policy.
- A good attestation record has four fields: employee name, date, policy version, and acceptance status.
- New joiners should attest before they get access to company AI tools, and everyone should re-attest at least annually or after a material policy change.
AI attestation is the process of confirming that every relevant member of your team has read, understood and accepted your AI usage policy. It's the bridge between having a policy and being able to prove it. Regulators, auditors and enterprise customers are increasingly asking not just "do you have an AI policy?" but "can you show your staff have read it?" Attestation is the answer to that second question, and without it, a policy is just a document sitting in a shared drive that nobody can prove anyone opened. Most teams that write a policy stop there, then get caught out the first time someone actually asks for the evidence behind it.
Why attestation matters for the EU AI Act
The EU AI Act's AI-literacy obligation under Article 4, in force since 2 February 2025, requires organisations to ensure staff have a sufficient level of AI literacy for their role. A policy distributed and acknowledged through attestation is the most direct way to evidence that duty. Without attestation records, you have a policy document but no proof anyone read it - thin evidence if a regulator ever asks how you assure literacy in practice. The obligation applies whether you're a five-person startup or a large enterprise; the Act doesn't set a headcount floor below which literacy stops mattering.
Does attestation apply to contractors and freelancers too?
If they use company AI tools or touch company data through AI, yes. The Article 4 duty and most internal risk logic don't distinguish between employment status - they care about who's actually operating the tools. A support lead at a Series A startup learned this the hard way when a contractor's unvetted use of a transcription tool surfaced during a customer security review; the fix was simple once attestation was extended to anyone with system access, not just payroll staff. It took an afternoon to close, and it closed the same gap for every future contractor automatically.
Why attestation matters for SOC 2 and customer audits
SOC 2 auditors and enterprise security questionnaires ask whether your AI policy has been communicated to staff, a question that traces back to the vendor and personnel management expectations in the AICPA's Trust Services Criteria. "Yes, we emailed it" is a weak answer if you can't show who received it and when. A timestamped attestation record for each employee, with a date and the policy version they accepted, is the audit-grade evidence that satisfies those questions without a follow-up call. See our SOC 2 and AI guide for how this fits into a wider audit.
What happens if someone never acknowledges the policy?
Chase it. An unacknowledged policy is a gap you're carrying, not a technicality. Set a follow-up window, seven to fourteen days is typical, and escalate to a manager if it's still outstanding after that. For anyone who genuinely won't engage, restricting their access to approved AI tools until they do is a reasonable, defensible position - far better than discovering the gap during an audit or after an incident traced back to that exact person.
What a good attestation process looks like
Send the policy to every relevant employee. Track who's opened, read and accepted it. Store a record with each employee's name, the date, and the policy version. Follow up on anyone who hasn't acknowledged within a reasonable window. Set a refresh cadence - at least annually, and whenever the policy is materially updated, whether that's a new approved tool, a changed data rule, or a fresh regulatory requirement landing on your desk. When someone new joins, they should go through attestation before they start using AI tools for work, not after their first week. Record the employee's role alongside the acceptance, too - it's the fastest way to spot that, say, the finance team never actually completed the round everyone else did.
Attestation versus training: are they the same thing?
No, and conflating them is a common mistake. Training builds understanding - a session or module explaining what the policy means in practice. Attestation is the record that someone engaged with the policy and agreed to follow it. The strongest setups do both: brief training content followed by an attestation step, so the acknowledgement isn't just a rubber stamp on an unread document. ISO 42001, the AI management system standard published in December 2023, includes its own competence and awareness clause that maps onto this same pairing, so organisations working toward certification usually need both pieces in place anyway.
Doing it without a manual process
Sending a PDF by email and tracking responses in a spreadsheet works for five people. It doesn't scale, and it doesn't produce reliable evidence once you're past a dozen staff or facing a real audit - spreadsheets get out of date the moment someone leaves or a new hire starts mid-quarter. ModelCharter's attestation module sends the policy to your team, tracks acknowledgement in real time, and stores the record for audit purposes. When someone joins or the policy updates, re-attestation is one click from the admin view rather than a fresh spreadsheet and a round of reminder emails.
Get attestation running this week
If your policy already exists but nobody has formally signed off on it, that's the gap worth closing first - it's usually the cheapest fix in AI governance, often a single afternoon of sending links and chasing replies. Pair it with a quick pass through the AI Tool Risk Directory to confirm the tools named in the policy still match what's actually in use, since a policy that lists tools nobody uses anymore, or misses ones that have crept in, undermines the value of the attestation record sitting on top of it. Close both gaps together and you've covered most of the distance between having a policy and being able to prove it.
| Field | Why it matters |
|---|---|
| Employee name | Ties the acknowledgement to a specific person, not a team or department |
| Date accepted | Establishes when literacy or awareness obligations were met |
| Policy version | Shows which set of rules the person actually agreed to, especially after updates |
| Acceptance method | Distinguishes a genuine click-through acceptance from an assumed email read |
| Role or department | Lets you spot gaps by team, useful when a specific function handles higher-risk data |
| Next review due | Drives the annual or post-update re-attestation cycle automatically |
“Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff.”