Hlinix.com

Chapter 13: AI Literacy in Practice — Building Your Training Programme

EU AI Act Implementation Guide · Full Chapter

What you will learn: By the end of this chapter, you will understand exactly what Article 4 requires, how to design an AI literacy programme that satisfies the regulation, how to scale it across different roles and organisational sizes, what documentation you need, and how to avoid the most common mistakes organisations make when approaching this obligation.

Why This Chapter Exists Separately

AI literacy appeared in every previous chapter as a baseline obligation. Chapter 10 introduced it as the sole mandatory requirement for minimal-risk systems. Chapter 12 confirmed it has been enforceable since 2 February 2025. But a single paragraph saying “train your staff” is not enough to implement it. This chapter provides the practical blueprint.

Article 4 is deceptively simple in its language but broad in its implications. It applies to every organisation that provides or deploys any AI system under the EU AI Act — regardless of risk category. A company with nothing but minimal-risk spam filters has the same Article 4 obligation as a company deploying high-risk recruitment AI. The depth and specificity of the training differs, but the obligation itself is universal.

This also makes AI literacy the single obligation most likely to be investigated early. It is already in force, it applies to everyone, and it is easy for an authority to verify: either you have training records or you do not.

What Article 4 Actually Says

Article 4 states:

“Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used.”

Five elements are embedded in this single sentence:

“To their best extent” — This is a best-efforts standard, not an absolute guarantee. You must demonstrate you took reasonable, proportionate measures. You are not required to achieve perfect understanding across every employee, but you must show genuine effort proportionate to your organisation’s size, resources, and AI usage.

“Sufficient level of AI literacy” — Sufficiency is contextual. A customer-service manager overseeing an AI chatbot needs different literacy than a software engineer maintaining the chatbot’s integration. Sufficiency is measured against the person’s role, not against a universal standard.

“Staff and other persons dealing with the operation and use” — This is broader than employees. It includes contractors, freelancers, temporary workers, and third-party personnel who interact with your AI systems. If an outsourced call centre uses your AI tools, their operators need training too.

“Taking into account their technical knowledge, experience, education and training” — Training must be adapted to the audience. A data scientist does not need the same introductory session as a non-technical HR manager. You must assess the baseline knowledge of each group and design training that fills the actual gaps.

“The context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used” — A system used to screen job applicants requires different literacy than a system that optimises warehouse logistics. The stakes, the affected populations, and the potential for harm shape what “sufficient literacy” means.

The Three-Layer Training Framework

Based on Article 4’s requirements and the practical realities of organisational training, the most effective approach uses three layers. Each layer targets a different audience with different depth.

Layer 1 — General Awareness (All Staff)

Every person in the organisation who may encounter AI systems — directly or indirectly — needs a baseline understanding. This is not a deep technical session. It is a foundational awareness programme covering what AI systems the organisation uses, what the EU AI Act is and why it exists, what the organisation’s obligations are at a high level, what each person’s responsibility is (recognising AI, using it as instructed, reporting concerns), and where to go for more information or to report issues.

Format: a single session of 30–60 minutes, delivered via live presentation, video, or e-learning module. Can be integrated into existing onboarding or annual compliance training.

Content depth: non-technical. No machine-learning theory required. Focus on practical awareness and organisational context.

Audience: all employees, plus contractors and third-party personnel who interact with the organisation’s AI systems.

Frequency: once at onboarding, then annually or when significant changes occur (new AI systems deployed, regulatory updates, organisational changes).

Layer 2 — Role-Specific Training (AI Users and Managers)

People who directly use, manage, or oversee AI systems need deeper understanding tailored to their specific role and the specific system they work with. This layer is where Article 4’s contextual requirements — “taking into account their technical knowledge” and “the context the AI systems are to be used in” — are primarily addressed.

For a human-oversight officer monitoring a high-risk system, Layer 2 covers the specific system’s capabilities and limitations, how to interpret its outputs, when and how to intervene or override, what constitutes an anomaly, and the escalation procedure. For a marketing team using AI-generated content, Layer 2 covers Article 50 transparency requirements, deepfake disclosure rules, metadata and watermarking practices, and editorial-review procedures. For an HR team using an AI-assisted screening tool, Layer 2 covers the system’s decision logic, known biases, human-review requirements, worker-notification obligations, and individual-explanation procedures.

Format: workshops, hands-on demonstrations, system-specific walkthroughs. Can include scenario-based exercises where participants practise identifying outputs, making override decisions, or handling edge cases.

Content depth: system-specific and role-specific. Includes practical exercises, not just information delivery.

Audience: anyone who directly interacts with, configures, manages, or makes decisions based on AI system outputs.

Frequency: at initial assignment to the role, when the system is updated or changed, and at least annually.

Layer 3 — Specialist Training (Compliance, Legal, Technical)

The smallest group by headcount but the deepest by content. This layer targets the people responsible for AI Act compliance, legal interpretation, technical implementation, and regulatory communication.

For compliance officers, Layer 3 covers the full regulatory framework — all 15 chapters of this guide — plus practical application: conducting FRIAs, managing conformity assessments, responding to regulatory inquiries, maintaining documentation. For legal counsel, Layer 3 covers the interaction between the AI Act, GDPR, sector-specific regulations, product-liability directives, and employment law. For technical leads, Layer 3 covers technical documentation requirements, data-governance standards, monitoring-system design, log-retention architecture, and security measures for AI infrastructure.

Format: extended training sessions, external courses, conference participation, ongoing self-study. May include certification programmes as they become available.

Content depth: comprehensive and detailed. Requires ongoing updates as regulatory guidance evolves.

Audience: typically 1–5 people in an SME, scaling with organisational size.

Frequency: continuous professional development, with formal refresher at least annually.

Designing the Curriculum

A curriculum that satisfies Article 4 must cover both general AI literacy and organisation-specific context. The following structure works for most organisations:

Module 1: What Is AI and How Does It Work? (Layer 1)

A non-technical introduction to AI concepts relevant to your organisation. This is not a computer-science course. It covers the difference between rule-based systems and machine-learning systems, what “training data” means and why it matters, that AI outputs are probabilistic (not deterministic), that AI systems can be wrong (hallucination, bias, error), and that AI does not “understand” — it generates outputs based on patterns. Use concrete examples from your organisation’s own AI systems. If you use a chatbot, show what it does well and where it fails. If you use a recommendation engine, demonstrate how it produces results and what happens with unusual inputs.

Module 2: The EU AI Act — What It Means for Us (Layer 1)

Covers why the regulation exists, the risk-based approach, your organisation’s specific obligations, and the enforcement timeline. Keep this practical: “We use systems X, Y, and Z. System X is classified as [category]. This means we must do [specific things]. Here is the timeline.”

Module 3: Your Role and Responsibilities (Layer 1–2)

Tailored to each audience segment. For general staff: “If you encounter an AI system in your work, here is what you need to know and do.” For AI users: “Here is how your specific system works, what to watch for, and when to escalate.” For managers: “Here is what your team must understand and how to verify compliance.”

Module 4: System-Specific Training (Layer 2)

One module per AI system, covering capabilities, limitations, correct use, known failure modes, override procedures, and reporting channels. This is where hands-on exercises belong.

Module 5: Regulatory Deep Dive (Layer 3)

For compliance, legal, and technical specialists. Covers the full regulatory framework, documentation requirements, assessment procedures, and enforcement preparation.

Documentation Requirements

Article 4 does not prescribe specific documentation formats, but demonstrating compliance requires records. The following documentation framework is sufficient for most regulatory inquiries:

Training Policy Document. A written policy stating the organisation’s approach to AI literacy, the three-layer structure, roles and responsibilities for training delivery, and the review cycle. This is a one-time document updated as needed.

Training Materials. The actual content — slides, videos, e-learning modules, handouts, exercise sheets. Retain current and prior versions to show how training evolves with the organisation’s AI usage and regulatory developments.

Training Records. For each training session, record the date, the participants (names, roles), the content delivered (module reference), the format (live, video, e-learning), and the duration. For e-learning, platform logs serve as records. For live sessions, attendance sheets or sign-in records.

Completion Tracking. A register showing which employees have completed which training layers, when, and when their next refresh is due. This is the document an authority is most likely to request.

Assessment Results (if applicable). If you include quizzes, tests, or practical assessments, retain the results. These are not mandatory under Article 4 but significantly strengthen your compliance position.

Gap Analysis and Remediation Records. If a training gap is identified — a new system deployed before role-specific training was delivered, a new hire who missed the annual session — document the gap, the remediation plan, and the completion of that plan. Authorities view self-identified-and-corrected gaps more favourably than gaps discovered during investigation.

Scaling for Different Organisation Sizes

Micro-enterprise (1–10 people, 1–2 AI systems)

Layer 1 and Layer 2 can be combined into a single 60–90 minute session covering “what we use, what the law says, and what you need to do.” Documentation can be a simple spreadsheet tracking who attended, when, and what was covered. The founder or a designated person handles Layer 3 responsibilities. Total initial effort: approximately 4–8 hours to develop materials and deliver the first session. Annual maintenance: 2–4 hours.

SME (10–250 people, multiple AI systems)

Separate Layer 1 (general awareness) from Layer 2 (system-specific). Deliver Layer 1 as an annual all-hands session or mandatory e-learning module. Deliver Layer 2 as team-specific workshops when new systems are introduced or during onboarding. Designate one person as the AI literacy coordinator to maintain records and schedule refreshers. Total initial effort: approximately 20–40 hours across development, delivery, and documentation. Annual maintenance: 8–16 hours.

Large enterprise (250+ people, many AI systems)

Integrate AI literacy into the existing compliance-training infrastructure. Layer 1 becomes an annual e-learning module alongside GDPR, anti-corruption, and other compliance training. Layer 2 is managed by department heads or system owners, with centrally provided templates and content. Layer 3 involves dedicated compliance staff with professional development budgets. Use a learning-management system (LMS) to automate tracking, reminders, and reporting. Total initial effort: varies significantly by existing infrastructure, but typically 100–300 hours across multiple teams. Annual maintenance: 40–100 hours.

Common Mistakes

Treating AI literacy as a one-time event. Article 4 is an ongoing obligation. A single session in 2025 with no updates, no refreshers, and no new-system training will not satisfy an authority in 2027. Build a recurring cycle from the start.

Making training too generic. A presentation about “what is artificial intelligence” downloaded from the internet does not meet the “taking into account the context” requirement. Training must reference your specific AI systems, your specific use cases, and your specific obligations. Generic content can supplement but not replace organisation-specific training.

Forgetting non-employees. Contractors, freelancers, outsourced teams, and third-party partners who interact with your AI systems are covered by Article 4. If you outsource customer service to an agency that uses your AI chatbot, their staff need training. Address this in contracts and verify compliance.

No documentation. Delivering excellent training without records is indistinguishable from delivering no training at all, from a regulatory perspective. If it is not documented, it did not happen.

Over-engineering for minimal-risk. If your organisation uses only minimal-risk AI systems (spam filters, recommendation engines, translation tools), you do not need a 200-page training programme. A focused, documented 60-minute session covering the basics is proportionate. Do not let the complexity of high-risk compliance deter you from fulfilling the simpler minimal-risk obligation.

Ignoring the “persons on whom” dimension. Article 4 requires you to consider the people affected by your AI systems, not just the people operating them. If your AI system processes data about vulnerable populations (children, elderly, disabled individuals), the training for the people operating that system must cover the specific risks and sensitivities involved. A chatbot serving general consumers requires different operator literacy than a chatbot serving elderly care-home residents.

Integration with Other Chapters

AI literacy is not an isolated obligation. It connects to and supports compliance across the entire AI Act:

For high-risk deployers (Chapter 6), the human-oversight officer’s competence depends on Layer 2 training. The ability to monitor system performance, interpret outputs, and intervene effectively is a direct function of the training they have received.

For high-risk providers (Chapter 7), the quality-management system must include training procedures for staff involved in design, development, testing, and post-market monitoring.

For FRIA and DPIA (Chapter 8), the assessment team must understand the AI system’s capabilities and limitations well enough to evaluate its impact on fundamental rights. This understanding comes from Layer 2 and Layer 3 training.

For limited-risk transparency (Chapter 9), the people responsible for implementing disclosure notices must understand what Article 50 requires and how to verify compliance in their specific deployment context.

For enforcement preparation (Chapter 12), documented training records are among the strongest mitigating factors when authorities calculate penalties. An organisation that can demonstrate systematic, ongoing AI literacy efforts is treated more favourably than one that cannot.

Self-Check

#QuestionYour Answer
1Is there a written AI literacy policy document?✔ / ✘
2Has Layer 1 (general awareness) training been delivered to all staff?✔ / ✘
3Has Layer 2 (role-specific) training been delivered to all AI system users and managers?✔ / ✘
4Has Layer 3 (specialist) training been delivered to compliance, legal, and technical leads?✔ / ✘
5Are training materials documented and version-controlled?✔ / ✘
6Are attendance/completion records maintained for every session?✔ / ✘
7Is there a completion-tracking register showing each person’s training status?✔ / ✘
8Is an annual review and refresh cycle scheduled?✔ / ✘
9Are non-employees (contractors, outsourced teams) included in the training scope?✔ / ✘ / N/A
10Is training content tailored to your organisation’s specific AI systems and use cases?✔ / ✘
11Does the training for high-risk system operators include system-specific capabilities, limitations, and override procedures?✔ / ✘ / N/A
12Is there a process for updating training when new AI systems are deployed or existing ones change?✔ / ✘

Summary

Article 4 AI literacy is the one obligation that applies to every organisation under the EU AI Act, regardless of risk category. It has been enforceable since 2 February 2025. The requirement is to ensure, through reasonable and proportionate measures, that everyone who deals with AI systems in your organisation understands what they are working with — adapted to their role, their technical background, and the context of use. A three-layer framework (general awareness for all staff, role-specific training for AI users and managers, specialist training for compliance and technical leads) covers the full scope. Documentation is essential: a written policy, training materials, attendance records, a completion register, and gap-remediation records. The effort scales with organisational size — from 4–8 hours for a micro-enterprise to 100–300 hours for a large enterprise in the first year, with proportionally smaller annual maintenance thereafter. AI literacy is not merely a regulatory checkbox. It is the foundation that makes every other obligation in this guide possible. Human oversight works only if the human is trained. Monitoring works only if the monitor knows what to look for. Incident response works only if the team recognises an incident. Invest in literacy first and the rest becomes substantially easier.

← Back to Blog Summary