01
What the AI Act requires on AI literacy
Article 4 of Regulation (EU) 2024/1689 requires providers and deployers to take measures to ensure, to the best extent possible, a sufficient level of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training, the context of use, and the persons on whom the system is used.
AI literacy is defined as the skills, knowledge and understanding that allow providers, deployers and affected persons to make an informed deployment of AI systems and to be aware of opportunities, risks and possible harms.
02
Who is involved and why
The Regulation distinguishes the provider, who develops or places on the market an AI system, from the deployer, who uses it under its own professional authority. Both roles have literacy obligations toward their own staff.
For high-risk AI systems, the Regulation also provides for a separate risk management system: an iterative process that runs throughout the system's lifecycle and requires constant review to identify and mitigate risks.
03
How to build the plan step by step
Steps
- Identify whether the company acts as provider, deployer, or both with respect to each AI system used.
- Map the people who operate or use the systems on the company's behalf, including their technical knowledge and prior experience.
- Define differentiated training content based on the context of use and the persons affected by the system's output.
- Revise the plan whenever the context of use, the systems employed, or the people involved change, keeping it consistent with the criteria of Article 4.
- Document the plan and the criteria used to tailor it to roles, education and training of the staff involved.
04
Hypothetical example
A company acting as deployer of an AI system for screening candidates might plan differentiated training sessions: one for the HR team directly operating the system, with deeper technical content, and a more general one for managers who receive its outputs, focused on opportunities and risks.
05
Checks before launching the plan
- Does the plan account for the technical knowledge and actual experience of the staff involved?
- Have the operational context and the persons affected by the system been considered?
- Is the plan updated when the context of use, the systems employed, or the staff involved change?
- Does the content clearly distinguish opportunities, risks and possible harms of the AI used?
06
What a software partner can help oversee
A company can ask a software partner to support traceability of the literacy plan: a record of the roles involved, evidence of training content assigned per profile, and a history of updates over time.
These are suggested operational choices, not stated features: each company should configure roles, review permissions and revise cycles according to its own internal setup and the context in which AI systems are used.
07
Frequently asked questions
Who must ensure AI literacy: only the provider or also whoever uses the system? Both, according to their respective roles and obligations.
Must training be identical for all staff? No, it should be adapted to the technical knowledge, experience, education and context of use of each group.
08
Next step
Start an internal mapping of the AI systems in use, the roles involved and the staff's levels of knowledge: this is the first concrete step toward building a literacy plan consistent with Article 4 of the Regulation.
FAQ
Frequently asked questions
Who is obligated to ensure AI literacy in the company?
Both providers and deployers of AI systems must take measures to ensure a sufficient level of literacy among their staff and anyone operating the systems on their behalf.
What exactly does 'AI literacy' mean?
It is the skills, knowledge and understanding that allow providers, deployers and affected persons to make an informed deployment of AI systems and to be aware of opportunities, risks and possible harms.
What does Article 9 provide for high-risk AI systems?
For high-risk systems, the Regulation provides for a separate risk management system: an iterative process throughout the system's lifecycle, requiring constant review and updates to identify and mitigate risks.
✓