Skip to main content
Practical guideEU AI Act5 min read

AI Literacy at Work: A Practical Training Plan

Plan AI training around the work your staff do, with practical exercises, useful records and an explanation of the amended Article 4 requirement.

AI-assisted guidance from RightCyber. Sources checked on 16 September 2026.

BylineWritten by RightCyber · Published by RightCyber

PublicationPublished · Updated

Source statusReviewed 16 September 2026 · Review due 16 October 2026

At a glance

Help staff decide what to put into an AI tool, how to check the answer and when to ask for help. Keep a record of what they learnt.

On this pageArticle contents

Share this article

LinkedInEmail

Getting a useful answer from an AI tool is one skill. Knowing when to question that answer is another. Staff need both, whether they're drafting a customer reply, checking a spreadsheet or summarising a meeting.

Start your training with a few familiar tasks and short exercises. Help people decide what they can put into a tool, how to check the result and when to ask for help.

What Article 4 now requires

The legal wording changed in July 2026. As checked on 16 September 2026, amended Article 4 requires providers and deployers within the Act's scope to take measures supporting the development of AI literacy among staff and others using systems on their behalf. Those measures should reflect their background, the context of use and the people affected. You can read the change in the adopted AI Omnibus.

The Commission's current explanation confirms that the obligation remains. The amended provision doesn't mandate a particular or “sufficient” level of literacy. Check training advertisements carefully if they quote the old wording or promise that taking one course guarantees compliance.

For a UK business, first check whether the activity falls within the Act's territorial scope. The practical steps below can help staff use AI carefully, whatever that assessment finds.

Find out how your team uses AI

Ask each team which AI features it uses, including those built into software you already pay for. A meeting summariser, spreadsheet assistant and customer-service chatbot may need different guidance, even when they come from the same supplier.

Talk through a recent task. What did someone put into the tool? What came back? Who checked it? Was the result sent to a customer, published or used to make a decision about a person?

Make it a conversation about improving the work. People may be reluctant to mention an unofficial workaround if they think they're about to get into trouble. Record the task and relevant settings, but keep private customer information out of the training document.

List everyday uses, tasks where mistakes would matter most and unanswered questions. Use that list to choose what to teach first.

Cover the decisions everyone needs to make

A first session could work through five questions:

  • Which tool can I use? Show people the services and accounts approved for their task.
  • What can I put into it? Explain what information is allowed and what needs further approval.
  • How do I check the answer? Practise verifying names, figures, sources and important claims.
  • Who could this affect? Discuss what an inaccurate or unfair result could mean for other people.
  • Who can help? Give staff a contact for unsafe, unexpected or out-of-scope uses and outputs.

Show a plausible answer with an invented reference and ask the group to check it. Can they find the original source? Does it support the claim? What should they do if it doesn't exist?

Walk through the checks, rather than simply telling people to be careful. Check they know when a draft is ready to send.

These are suggested exercises. Article 4 doesn't prescribe this syllabus, a particular course length or these five questions.

Use examples that fit the job

Your marketing team could check a generated product claim against an approved specification. Your service team could compare a draft reply with the refund policy. A manager could look for missing information in an AI summary before using it to make a decision.

For a hypothetical recruitment exercise, give staff fictional candidate notes and a generated summary that leaves out relevant experience. Ask what they would check before relying on it. Use invented details throughout so that the exercise doesn't expose real applicants' information.

People who choose or configure tools need practice with supplier questions, permissions, limits on use and routes for reporting problems. Reviewers need time and subject knowledge to challenge outputs that could have serious consequences. Being the person nearest the screen doesn't make someone a qualified reviewer.

Keep a useful record of the session

The Commission's AI literacy questions and answers says a certificate isn't required. Organisations can keep internal records of training or other guidance instead. It also says Article 4 doesn't mandate a particular governance structure.

Record the date, who took part, which tools you discussed, the exercises you used and what you agreed to change. Keep the guidance you gave staff. If the session revealed confusion about customer data, note the updated input rules and who explained them to the team.

A commercial training certificate can show attendance. Keep a record of how the guidance fits your tools and people's jobs too.

Check what people can put into practice

An attendance list shows who turned up. A short exercise tells you more about what they understood. Ask what they'd verify, what information they'd keep out of the tool and when they'd ask for help. Follow up on uncertainty.

Give staff a short reference sheet they can use at work. Include approved uses, data restrictions, checking steps and a named contact. Put it somewhere they can find quickly when they're unsure about an answer.

Update the training when a tool changes, another team starts using AI or an error exposes something you've missed. After a month, you could review staff questions and adjust the programme. That's a suggested management routine, not a statutory deadline.

To get started this week, choose one team and a task they do regularly. Agree what information they can use, practise checking a flawed answer and write down the improvements. Their questions will help you plan the next session.

Provenance

Sources reviewed

Reviewed 16 September 2026

Sources reviewed by RightCyber on 16 September 2026. A source’s classification describes where it came from; it is not a blanket claim about every source.

Disclaimer

RightCyber is independent and is not affiliated with or endorsed by the European Commission or any source linked here. This article gives general information. It isn't legal advice and doesn't establish whether your organisation complies. Check how the rules apply to your work and get advice where you need it.

Clarifications

Frequently asked questions

Is a particular AI literacy certificate compulsory?
No. The European Commission says Article 4 doesn't require a certificate. You can keep internal records of relevant training and guidance to show what you've done. A certificate of attendance doesn't guarantee legal compliance.
Did the AI Omnibus remove the AI literacy obligation?
No. Amended Article 4 still requires providers and deployers within scope to take measures supporting the development of AI literacy. It no longer mandates a particular or sufficient level of literacy. The measures should reflect who uses the systems, the context and who could be affected.
Should everyone receive identical AI training?
Some basics will be useful to everyone. The exercises should fit each person's tools and responsibilities, though. Someone drafting an internal note needs different practice from someone approving customer replies or checking recommendations that could seriously affect another person.

Continue reading

Continue with a related article

Help staff protect the accounts they use for work. Read how stronger sign-ins, recovery controls and secure devices work together.

Keep exploring

Browse the RightCyber Blog
  • People and account security

    How Cyber Attacks Often Start

    Many incidents begin with an ordinary request to click, reset, scan, or pay. Verify money movements, bank-detail changes, and account recovery through a separate trusted channel every time.

  • People and account security

    Why MFA Isn't Enough on Its Own

    MFA still blocks a huge amount of password abuse, but phishable prompts and stolen sessions remain. Move important accounts towards passkeys or FIDO2, then review recovery, session controls, and monitoring.

  • Resilience and incident response

    Why Small Businesses Get Attacked

    Small firms can be reached by automated attacks and by disruption to organisations they depend on. Map critical suppliers, protect important accounts, test restoration, plan for serious downtime, and resolve incidents fully.