AI literacy (Article 4 of the AI Act): what training it requires and how to evidence it

It is the most ignored obligation in the entire EU Artificial Intelligence Act, and one of the first to enter into force: since February 2025, every company using AI systems must ensure its staff have a sufficient level of “AI literacy”. Not only those who develop AI: those who use it. If your teams work with a chatbot, generative AI tools, scoring systems or any software incorporating AI, Article 4 applies to you.

Most companies have done nothing about it — many do not even know it exists. This article explains what exactly it requires, from whom, and how to comply in a proportionate, documentable way.

What Article 4 says

Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training, the context of use, and the persons affected.

Three things stand out:

It applies to almost everyone. It does not distinguish between high risk and minimal risk: deploying or providing any AI system is enough. The company using generative AI tools for marketing is covered, just like the one developing models.

It is a modular obligation of means. “To their best extent”, “taking into account” each person’s profile and the context: the training for a model developer and for a salesperson using an AI assistant need not be the same. The rule demands proportionality, not a master’s degree for the whole workforce.

It reaches third parties acting on the company’s behalf. “Other persons dealing with… on their behalf”: contractors, agencies and external staff operating your AI systems count too.

What “AI literacy” means in practice

The Regulation defines it as the skills, knowledge and understanding that allow an informed deployment of AI and awareness of its opportunities, risks and possible harms. Translated into a training plan, the reasonable minimum content covers:

  • What the AI in use is and is not: capabilities and limits of the company’s specific tools (not general theory — your tools).
  • Typical risks: generative AI errors and fabrications (“hallucinations”), bias, over-reliance on outputs, confidentiality of what is entered into the tools.
  • The internal framework: the company’s AI policy — which tools are authorised, for which uses, which data must never be entered, when human review is required.
  • The legal duties of the role: whoever manages the chatbot must know the Article 50 notice; whoever uses AI with personal data, the GDPR implications; whoever uses it in decisions about people, the reinforced safeguards.

How to comply proportionately: the four-step plan

1. Map who touches AI and how. The starting point is the AI system inventory — if you followed our inventory article, you already have it: add a column with the roles using each system.

2. Define training levels by profile. Three levels usually suffice: basic (all staff using general-purpose AI: 1-2 hours on risks, internal policy and good practice), operational (those operating specific systems with impact on clients or decisions: tool-specific training including its legal obligations) and advanced (those developing, configuring or supervising systems: in-depth technical and regulatory training).

3. Deliver with what you have. The rule requires neither certified external training nor a specific format. Internal sessions, online modules, or the AI policy explained at onboarding all count. The AESIA guides — recently updated — are free base material aligned with the Spanish supervisor’s criteria.

4. Document everything. This is where compliance is won or lost: the obligation is one of means, so the evidence of having taken measures IS the compliance. Keep the training plan, the materials, dated and signed attendance records (or the e-learning platform log), and the refresher calendar. In an inspection, that file is the answer.

Frequent mistakes

  • Confusing it with technical training. This is not about teaching people to code: the salesperson needs to know what not to paste into a public chatbot, not what a transformer is.
  • One talk and nothing more. The state of the art changes (and so do your tools): without periodic refreshers, the measure ages. Annual is a defensible rhythm.
  • Forgetting external staff. The agency running your marketing with generative AI acts “on your behalf”.
  • Training without an AI policy. Training explains the rules; if there are no written internal rules, there is nothing to explain. If your company has no AI use policy yet, that is step zero.

What is the actual risk

Article 4 carries no specific fine in the Regulation’s penalty regime, which has led some to shelve it. A miscalculation: literacy works as a transversal obligation that colours everything else. In any incident — a discriminating chatbot, a data leak through misuse of generative AI, an automated error harming a client — the first thing the authority or the court will examine is whether the company trained its people. A breached Article 4 makes every other file a worse file: it aggravates negligence, weakens the defence and can ground liability for failure of oversight. And conversely: the documented training file is the first mitigating factor you put on the table.

How we can help

At Ferrer-Bonsoms Abogados we prepare the complete AI literacy package: internal use policy, a tiered training plan adapted to your systems, session materials and the documentary record template that serves as compliance evidence.

Contact us →


AI Act series: service page — AI Act compliance · The AI Act after the Digital Omnibus · How to inventory your AI systems · Alert: AESIA updates its 16 guides · Chatbots and Article 50. Next article: integrating the OpenAI or Anthropic API into your SaaS — what obligations you take on.

Scroll to Top