A register ordered by consequence, not by frequency

Asking which mistakes ruin company AI training invites an answer measured in percentages: how many companies make a given mistake, how often it repeats. CIAD does not have that answer. There is no internal survey across clients and no measured incidence to build a ranking from.

What follows instead is a register of nine mistakes CIAD uses as its own structured practice when preparing and evaluating company AI training. Because there is no measured frequency, the rows are ordered by how serious the consequence is if the mistake happens. The order reflects estimated severity, not how common each mistake is; the register does not measure or claim frequency.

The register has five columns: the mistake itself, a warning sign that lets you catch it before it does damage, the cost of letting it happen, the fix to apply before the first session, and the repair to apply if the mistake has already occurred. The descriptions are qualitative; you will not find a percentage, a company count or an interval anywhere in them.

The register

MistakeEarly warning signCost of failureFix before trainingRepair after
No link to a concrete work taskThe programme shows generic tool demos with no reference to the team’s actual processParticipants can operate the tool but do not know where to apply it, so the investment never shows up in the workBefore booking, name one to three work tasks the training should support, and put them in the brief for the trainerAfter the first run, match the content retrospectively to a concrete task; rework or trim what does not match
Training treated as proof of complianceThe stated goal is framed as satisfying the AI Act, and the main measure of success is attendance or a certificate issuedThe company holds a formal record, but participants cannot use the tool safely in normal workWrite the goal as a concrete skill, and check the current scope of the Article 4 obligation with your own lawyerAdd a follow-up practical session tied to a real task, even after the formal programme has already run
No boundary on what company data may enter which toolParticipants ask during the course what they are allowed to input, and the trainer answers only in general termsAfter training, people put sensitive or personal data into public tools because no specific rule existsHave a written rule on permitted and forbidden inputs ready before the first courseWrite the rule immediately and put it first in the next session
Identical content for every role regardless of the workThe same slide deck goes to sales, operations and legal with no change to the examplesPart of the audience sits through material outside their own work, and the transfer to daily use dropsUse examples drawn from each group’s own operationSplit the next run by role and rework the examples, even if it shortens each session
No protected time to use the tool after trainingThe course ends and the company offers no space to practise on a real task in the following weeksThe learned method fades quickly; people revert to the old way of working or improvise with the tool unsupervisedSchedule dedicated time after training for a first independent attempt on a real taskIf the gap has already grown, repeat only the key block in a shorter form
No baseline record to measure change againstAfter the course, the company has no recorded state from before training to compare againstThe company cannot decide whether to continue, adjust or stop, because there is nothing to compare againstRecord the baseline state of the chosen work task before the first courseIf the baseline is missing, start collecting it immediately and base later decisions on it going forward
Trainer unfamiliar with the team’s actual tools and operationsExamples in the material come from generic vendor templates and do not match the team’s environmentContent stays theoretical, and participants cannot see how to carry the method over to their own taskRequire a preparatory conversation with the process owner in the trainer’s briefAdd a shorter, internally led session to fill the missing context after the first run
Scope and budget driven by the vendor’s price listHours and group sizes come mainly from the vendor’s standard offer, not from the number of tasks that actually need to changeThe company overpays for content nobody uses, or the programme gets cut below what is needed to build the skillDerive scope from the number of concrete tasks named in the first row of this registerAfter the first run, compare the content actually used against what was booked, and adjust the next budget
Agreed rules and examples never written down anywhereAfter the course there is no shared record of approved tools, rules or good examplesKnowledge stays with the participants only; new joiners have nothing to draw on, and it disappears when a key person leavesDecide before training who will record the agreed rules, and where, so they stay accessible outside the course itselfWrite up retrospectively what was agreed and store it where the team actually looks

On the second row: since Regulation (EU) 2026/1744 amended Article 4 of the AI Act, the current duty is to take measures supporting the development of AI literacy. It does not require guaranteeing a particular level for any individual, it does not prescribe a training format or duration, and it does not require a certificate. If a company keeps an internal training record regardless, that is its own decision; the current wording of the law does not require that record in this form.

On the fifth row: no protected time to practise after a course is one reason unsupervised, ungoverned AI use spreads inside companies. Wider governance questions around that pattern are covered in securing AI use across the enterprise. The third row connects directly to the specific question of what is and is not safe to put into a public tool, covered in is it safe to put company data into ChatGPT.

Working through the register after a first run

After the first training run, go through the register row by row rather than relying on a general impression of how the course went. For each row, note whether the described warning sign appeared, how you noticed it, and what repair followed. A row whose warning sign never appeared in your operation can move to the back of your attention for the next run, or be dropped from active tracking. A mistake you hit that the register does not cover should be added as a new row with the same five-column structure, so it stays visible next time.

The row about a missing baseline record can only be checked this way if the measurement is designed before the first course runs. Compliance framing tied to a deadline, the mistake in the second row, is easiest to picture against the fuller obligation timeline in the AI Act’s compliance deadlines from February 2025 to August 2027. Budget derived from a vendor’s price list, the eighth row, connects to the wider cost picture in what deploying AI actually costs a company.

What matters most: first training versus a repeat run

For a first training programme, the highest-cost mistakes are the ones that are hard to fix after the fact: no link to a concrete task, no boundary on input data, and no baseline record for later comparison. These three rows are worth resolving before the course starts at all. Fixing them retrospectively tends to cost more than having them ready in advance, and for the data-boundary row, the damage may already have happened by the time anyone notices.

For a repeat run, where the company has already been through the programme once, the focus shifts to retention and transfer: protected time to use the tool afterwards, a written record of agreed rules outside participants’ own memory, and a scope for the next run that matches what the first run actually used. A company that got the data-input boundary right the first time but never created space for regular use risks starting its second run from close to zero. The scope and budget row can only be properly assessed after one full cycle has run its course.

Sources and limits

Four sources were verified against the dates given beside each link. Regulation (EU) 2026/1744 and the European Commission’s opinion on AI literacy support the description of the current shape of the Article 4 obligation. They do not support any claim about how frequent mistakes in company AI training are; this article makes no such claim. The structure of NIST’s AI RMF, its govern, map, measure and manage functions, inspired the register’s own layout of warning sign, cost, prevention and repair, but the framework itself does not describe company training. The NIST AI RMF Playbook describes its own content as voluntary suggestions for optional use; the register in this article carries the same character, an offered CIAD practice built without internal client data and without a measured frequency. Which specific categories of data a company may put into a given tool, and what legal basis covers that processing, needs assessment by that company’s own lawyer or data protection officer; this article does not substitute for that assessment.

Frequently asked questions

Is this a statistic showing the most common training mistakes?

No. CIAD has no internal data on how frequently these mistakes occur across companies, no client survey and no incidence count. The register orders mistakes by how serious the consequence is if they happen, not by how often they happen. Treat it as a structured checklist to work through, not a measured ranking.

Does a company need a certificate from AI training under the AI Act?

No. Since Regulation (EU) 2026/1744 amended Article 4, employers must take measures supporting the development of AI literacy. It does not require guaranteeing a particular level for any individual, it does not prescribe a training format, and it does not require a certificate. A company may keep an internal training record if it wants to, but the current wording of the law does not require one in that form.

Is it enough to work through the register once, before the first training?

No. The register is meant for repeated use: before training to prepare mitigations, and after the first run to check which warning signs actually appeared. A row that turns out not to apply to your operation can be deprioritised for the next run. A mistake you encounter that the register does not cover should be added as a new row with the same structure.

Is a risk register the same thing as a post-training satisfaction survey?

No. A satisfaction survey captures only how participants felt about the session. The register instead tracks whether a specific mistake in preparation, content or follow-up use undermined the value of the training for the actual workflow, regardless of how participants rated the session. Both are worth tracking together, since they measure different things.

Do the preventive fixes need to be in place before a company books a trainer?

For three rows, yes: the data-input boundary, a goal tied to a concrete task, and a baseline record of the state before training only work if they exist before the course starts. Fixes for follow-up use and for writing down what was agreed can still be arranged between booking and the first session.

SOURCES AND VERIFICATION

reviewed Lukáš Dlouhý ·