---
title: "AI literacy in a telco: the problem is scale"
url: https://zerofive.ai/en/blog/compliance/ai-literacy-telecom-operators-scale
canonical: https://zerofive.ai/en/blog/compliance/ai-literacy-telecom-operators-scale
language: en
published: 2026-07-28
updated: 2026-09-23
author: "ZeroFive.AI"
tags: AI literacy, telco, NIS2, clause 7, outsourcing
abstract: "Thousands of people, many not employees. The few roles needing individual evidence and what to reuse from the existing NIS2 framework."
---

# AI literacy in a telco: the problem is scale

**In short.** In a telco the problem with AI training is scale: thousands of people across call centres, stores and the sales network, most of whom are not employed by the operator. The uniform training that works at those numbers covers the literacy obligation and doesn't cover clause 7, which asks for competence by role. The answer isn't training everyone the same way, it's separating the few roles needing individual evidence from the mass that needs awareness.

Telecom operators have vast, well-run training frameworks built on compliance, safety and product. AI slots in easily as a module, and that is both the advantage and the risk: a module added to a system designed for scale produces no specific competence on any system.

## The perimeter is wider than the payroll

Clause 7.3 speaks of people working under the organisation's control, and in a telco that perimeter includes the outsourced call centre, franchised stores, agents and installation technicians. These are people using assistance, quotation and diagnostic tools daily, and who in most cases appear in no operator training plan.

This is the first gap to close, and it is contractual work. Competence requirements belong in service contracts with partners, alongside an obligation to supply evidence.

The second gap concerns turnover. In a call centre annual churn is high, and an annual training plan covers a population that has half changed in the meantime. What's needed is a trigger tied to a person joining, not to the calendar.

## The roles needing individual evidence

For the vast majority, awareness is enough: what the tool does, when it needs checking, who to report to. For three groups the evidence has to be named.

**Those working on credit assessment.** This is the surprise in a telco. Device instalment plans involve an assessment of the customer's creditworthiness, which falls under Annex III, and anyone working on that process carries full competence obligations.

**Those exercising human oversight over critical network systems.** Not under the AI Act, where those systems stay low risk, but under NIS2, which requires demonstrable competence on resilience.

**Those approving platform adoption.** In a telco adoptions often run through procurement, and whoever signs needs to know what they are approving in terms of role and obligations.

## What to reuse from NIS2

The framework built for NIS2 already covers part of the work, and mapping it is worth doing before building.

| Element | Exists for NIS2 | What's missing for AI |
|---|---|---|
| Security and resilience training | Yes, structured | Extension to AI systems |
| Evidence tracking | Yes, by obligation | Link to role and system |
| Critical supplier management | Yes | AI competence requirements in contracts |
| Operational risk culture | Yes | Translation to risk for the individual |
| Effectiveness verification | Exercises | Practical cases on AI systems in use |

The last row is the easiest to close and the most often ignored. Telcos run exercises on security incidents, and the same format applied to an anomalous AI output produces effectiveness evidence that a questionnaire doesn't give.

## The module no vendor can write

As in every sector, the useful part requires information only the operator holds: which systems are live on which processes, which edge cases have already surfaced in support, who to report anomalous behaviour to and what happens next.

In a telco this translates into short, repeatable content, because it has to reach thousands of people with high turnover. Thirty minutes per system, refreshed when the system changes, distributed through the same channels already used for product.

## Where to start

The prerequisite is the [AI system inventory](/en/blog/compliance/ai-system-inventory-iso-42001), built in the knowledge that many systems arrived inside network vendor platforms and were never classified.

From there the matrix gets built, described in [a roles-competence matrix for AI](/en/blog/compliance/roles-competence-matrix-ai), separating the few roles needing individual evidence from the wider population. The full requirements are in [clause 7 explained without jargon](/en/blog/compliance/clause-7-iso-42001-explained).

The sector's regulatory picture is on the [AI governance for telecom operators](/en/sectors/telco) page.

Our approach to role-based tracks is on the [AI Training](/en/services/ai-training) page. To review your operator's plan, you can [book a meeting](https://calendly.com/fabiolalli/zerofive).
