AI Literacy & AI Act training

Corporate AI Literacy training: bring your company into line with the AI Act.

Since 2 February 2025, artificial intelligence literacy has been mandatory for all employees who use AI tools. We prepare your team with practical courses, a final assessment and the documentation you need the day someone asks for it.

The regulatory framework

The obligation already exists.
And it has been in force for over a year.

Next to this you'll find Article 4 in full, in the official English text. It's little more than ninety words, and it's everything the Regulation says about training. It's worth reading, because it already contains the two things that concern you: the obligation applies even to those who merely use artificial intelligence, and it extends to anyone operating the systems on your behalf. If someone in your company opens a conversational assistant to fix an email, you're within the perimeter.

REG. EU 2024/1689 · ARTICLE 4
AI literacy

"Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used."

None of these words says "when you have time".

From2 Feb 2025

The obligation takes effect

Article 113 says it without margins: "Chapters I and II shall apply from 2 February 2025". Article 4 sits in Chapter I. From that day every organization that employs AI systems must be able to demonstrate that it has trained those who use them. That date is long gone.

From2 Aug 2025

Penalties and national authorities

Again Article 113: from this date Chapter XII on penalties and Chapter VII on governance apply. Member States designate the competent national authorities and define their own penalty regime, which builds on the thresholds set by the Regulation.

From2 Aug 2026

Full supervision

"It shall apply from 2 August 2026": it's the general rule of the Regulation, and from then on market surveillance authorities operate in full. It's the date to keep in mind while planning this year's training budget, because it's when inspection stops being a hypothesis.

"No fine is written next to Article 4."

— But training is the prerequisite of the obligations that do carry a fine. Whoever doesn't know how a tool works can't supervise it.

The perimeter

It concerns more people
than you have in mind.

When we do the initial survey, the number of people in the company already using artificial intelligence is almost always higher than what whoever called us expected. Rarely out of disobedience: more often because nobody had said anything, one way or the other.

01

Those who use it, even just occasionally

Marketing generating texts, administration having documents summarized, customer care preparing replies, the tech team getting code explained. Article 4 doesn't speak of job duties: it speaks of "staff" and of "other persons dealing with the operation and use of AI systems" on your behalf. That "on their behalf" brings in external collaborators and suppliers too.

Art. 4 AI Act Staff External collaborators
02

Those who decide and answer

Owners, HR, department heads, DPOs. They need a different level: which tools to authorize, how to put it in an internal policy, when a use falls among the high-risk ones. Because that's where Article 26 kicks in, which for high-risk systems is clear: "deployers shall assign human oversight to natural persons who have the necessary competence, training and authority". Training stops being good practice and becomes a requirement for those who oversee.

Art. 26 · high risk Human oversight Internal policies
03

What "sufficient level" means

The Regulation doesn't set a number of hours, and it's not an oversight. Recital 20 clarifies that the necessary notions "may vary with regard to the relevant context", and Article 4 requires weighing knowledge, experience and context of use. In other words: an identical course for everyone is almost always the wrong answer, because it leaves the truly exposed uncovered. We start from a survey of roles and build the pathways from there.

Recital 20 Proportionality Role analysis

What the package includes

Three modules on what happens
when you press enter.

No history of artificial intelligence and no diagrams of how neural networks work. The content starts from the tools your team already has open in the browser and the mistakes made when using them.

MODULE 01 · SAFE PROMPTING

Using AI without letting data out

What can be pasted into a public chat and what must never be pasted. Personal data, confidential documents, client information. How to get the same result by rephrasing the request, which tools the company has authorized and why, what to do when it has already happened.

MODULE 02 · BIAS AND HALLUCINATIONS

Recognizing a wrong answer

Models produce correct and invented statements with the same confidence. The module trains you to tell them apart: how to verify a source, which questions generate the most errors, where biases hide in training data and which decisions must never be delegated to an unchecked output.

MODULE 03 · PRIVACY, DATA AND ETHICS

The rules applied to everyday work

GDPR and the AI Act translated into concrete behavior: when you need to tell a client they're interacting with an AI system, how to mark generated content, which uses fall among the high-risk ones, what to write in the record of processing. With cases from your sector, not generic examples.

How it's delivered

Three formats.
Traceability is in all three.

A

Asynchronous e-learning

Everyone follows when they can, from wherever they like. It's the format that best handles shifts and multiple sites, and it's the one that produces the documentation on its own: accesses, viewing minutes, video completion and final test results end up in a report with nobody having to transcribe them.

B

Classroom or videoconference

Live sessions with exercises on cases you bring. It works well with homogeneous groups and when you need to bring out what people are already doing with AI without saying so. Attendance register and tests remain the same.

C

Blended format

The most requested combination: e-learning for all staff, a live session for those with decision-making responsibilities. It covers the full perimeter while keeping the time taken away from work low.

Who we work with

Whoever calls us, usually,
has already received the question.

Frequently asked questions

The answers, no detours.

Who is obliged to provide training in the company?

The obligation falls on the company, not on the individual employee. Article 4 addresses "providers and deployers of AI systems", and deployer in the Regulation's language is you who use those systems, even if you didn't build them. The perimeter of people is defined by the rule itself: staff "and other persons dealing with the operation and use of AI systems on their behalf". That "on their behalf" is the part that gets missed, and it's the one that brings in freelancers, agencies and suppliers. The form of the contract doesn't matter, what matters is the actual use: if someone in administration has a document summarized by a conversational assistant, that person is in. The extent of the training, instead, must be calibrated to role and risk, because someone using AI to rewrite an email needs something different from someone using it to screen résumés.

Can the courses be done online via e-learning?

Yes, and the Regulation is deliberately open on the point. Article 4 says providers and deployers "shall take measures" to ensure a sufficient level of literacy: it prescribes the result and leaves you free on the how. There is therefore no imposed format and no minimum number of hours to respect. Asynchronous e-learning is the most practicable formula for those with shifts or multiple sites, and it has a considerable documentation advantage, because the platform records accesses, viewing times and completion on its own: the "measures" become demonstrable without anyone having to reconstruct them by hand. If you prefer the classroom, in person or by videoconference, we do that. The most requested combination remains e-learning for everyone plus a live session for those with decision-making responsibilities.

Do you issue a certificate valid by law?

Here we give you the exact answer, which is more useful than the convenient one: an official AI literacy certification does not exist, for us as for anyone else. The Regulation devotes an entire chapter to notified bodies, conformity assessment and certificates, but it concerns high-risk AI systems: for staff training, Article 4 merely asks that you "take measures", without establishing either a register or a certification scheme. Whoever sells you a certificate "compliant with the law" is selling you something the law does not provide for. The Article 4 obligation rests with you as an employer, and what matters is being able to demonstrate that you have fulfilled it. That's why we deliver a complete file: attendance and access register, test results with date and score, named certificates for each participant, teaching program and materials used. It is the documentation an authority or an advisor asks for during an inspection, and it's the only thing that currently has concrete value.

Is there a fine if we don't do the training?

Not in the form it's told to you, and here it pays to know how things stand better than those who try to scare you. The 35 million euros circulating online are in Article 99, paragraph 3, and concern one thing only: the violation of the ban on prohibited AI practices in Article 5. Not training. The next paragraph, the one for 15 million, lists one by one the obligations subject to penalties: Articles 16, 22, 23, 24, 26, 31, 33, 34 and 50. Article 4 is not on that list, and you can check it in two minutes. That said, the convenient conclusion would be "so let's forget it", and it is wrong for three concrete reasons. Literacy is the prerequisite of the obligations that are penalized: Article 26 demands that human oversight of high-risk systems be assigned to people with "the necessary competence, training and authority", and without training you can't tick that box. It's the first thing asked when an inspection starts, because it's the easiest to check and the hardest to improvise after the fact. And in case of damage caused by clumsy use, "nobody had explained it to them" is a position that can't be defended, either in front of a client or in front of a judge.

How long does it take and how much does it cost?

The basic modules take between three and six hours per person, distributed as you prefer over a few weeks. The quote depends on how many people you involve, how many different profiles there are and the chosen format, with a per-person cost that drops quite a lot for large groups. The written quote comes after a twenty-minute call in which we find out who in the company already uses AI, which as we said is almost always more people than you imagine.

How often should it be repeated?

Once a year is the reasonable rhythm, plus an update when something substantial changes: a new tool adopted in the company, a new obligation entering into application, new people joining. The Regulation doesn't set an explicit deadline, but a training file stuck at two years earlier is hard to sustain as a "sufficient level" in front of whoever is checking.

The first step

Find out who in the company
already uses AI.

We start from a survey of roles and the tools actually in use. From it come the perimeter of people to train, the pathway for each profile and the written quote. We do the survey in one call, with no commitment.