AI literacy under Article 4 · why a one-page memo does not discharge the duty
Since 2 February 2025 the AI Act has required sufficient AI literacy among your own staff. What that means in practice, which level fits which role, and how to evidence where you stand.
- Author
- SIMOSphere AI
- Published
- Reading time
- 5 min read
- Topic
- AI Training
In a lot of companies the AI literacy duty was discharged with a circular email: a one-page memo with five rules, a read receipt, a tick in a list. That is understandable, because the provision is short and names no number of hours. It still does not suffice, and the reason is in the wording.
What Article 4 requires
Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf.
The provision has applied since 2 February 2025, the date on which Chapter I of the Regulation entered into application under Article 113. It sits in Regulation (EU) 2024/1689 and is aimed expressly not only at makers of AI systems but at every deployer.
Three words carry the weight. Measures means more than an announcement. Sufficient is a relative standard that follows prior knowledge and intended use. And other persons pulls in contractors, temporary staff, and service providers who operate the systems on your behalf.
Why the absence of a fine changes nothing
Article 4 does not appear in the penalty catalogue of Article 99. Concluding that the duty is toothless mistakes where it bites: it comes up in every supervisory enquiry, in every assessment of a high-risk system, and in every dispute about a decision that rested on a machine recommendation. At that point the question is not whether you trained anyone. It is what you can show.
What sufficient means in practice
Sufficient does not mean everyone has to be able to explain a transformer. It means every person can judge the systems they work with. Four abilities cover it.
- Judging what a system is good for and what it is not.
- Recognizing a wrong answer before it gets used downstream.
- Knowing which data may go in and which may not.
- Knowing when a person has to decide and when they do not.
The second one is the hardest, because a fabricated answer usually sounds better than a correct one. It cannot be acquired by listening. It is acquired by working through cases where the system gets it wrong.
Five levels, matched to roles
A training path needs levels, because a board member and a software engineer are not asking the same question. The academy runs five.
- Two hours for decision-makers, live online, up to ten participants. The model landscape, use cases by business unit, risks. For executives, department heads, and supervisory bodies.
- Four hours on data protection and language models, up to twelve participants. Processing agreements, classifying your own use cases, redacting personal data. For data protection officers and compliance.
- One day in the workspace for heavy users, up to eight participants. Skills, tools, your own connectors, reading audit entries. For the people who work with it every day.
- Two days for engineers, hybrid, up to six participants. From the first system prompt to a skill in production, testing, and continuous integration.
- Five days of certification with an exam, up to eight participants. Architecture, custom tools, compliance and audit logging, one day on site with a pilot customer.
Length, group size, agenda, and terms for each level are on the SIMO Academy page. Every level is also available in house.
Which level for whom
A workable rule of thumb: whoever decides needs level one. Whoever works with the output daily needs level three. Whoever classifies use cases or owns contracts needs level two. Levels four and five concern few people, which is exactly why it pays to hold that knowledge in house rather than renting it indefinitely.
The purpose is capability, not dependency. The benchmark is a team that shapes its own roles and tools after the training without having to call anyone.
How to evidence where you stand
An attendance list on its own does not carry an enquiry. Four documents do.
- A mapping of which role in the company needs which level, with the reasoning.
- Per-person evidence of the level attended, with date and content.
- A rule for new hires and for service providers operating systems on your behalf.
- A date for the refresher. What was learned in 2025 describes a model landscape that no longer exists.
If you already keep the platform's audit trail, part of this comes for free: it shows who uses which system and how, which makes training needs visible instead of assumed.
What training does not replace
It does not replace architecture. A well-trained team working with a system that names no sources and logs no calls cannot apply its competence at all. You can only judge what you can trace.
Which is why the two topics belong together. The technical side is covered in the article on orchestration for mid-sized companies; where the line between preparation and decision runs in daily work is covered in the article on the five teammates.