Introduction
Over the past few months, many companies have put together AI guidelines. A PDF with rules of conduct, sent out by email, maybe filed away on the intranet — done. But the EU AI Act adds a new dimension here: AI literacy becomes a documented obligation. It's no longer enough to simply set rules. Companies must be able to demonstrate that their teams have the AI competence needed to apply these rules safely in everyday work. This poses new challenges for existing training processes — but it also offers the opportunity to use AI tools more efficiently and with fewer errors. This article shows exactly what the EU AI Act requires and how you can establish AI literacy in your company in a pragmatic and demonstrable way.
What Does AI Literacy Mean in the Context of the EU AI Act?
AI literacy — or AI competence — refers to the ability to understand, critically evaluate, and responsibly use AI systems. In the context of the EU AI Act, this isn't about deep technical programming knowledge, but about a practical understanding of risks, legal boundaries, and correct application.
The EU AI Act distinguishes between different roles. For most companies, the role of deployer (operator/user) is relevant: you use existing AI tools like ChatGPT, Microsoft Copilot, or specialized industry software in your everyday work.
In practice, AI literacy means:
- Data protection: Knowing what data may be entered into AI tools.
- Quality control: Recognizing when AI outputs (e.g., hallucinations) need to be checked.
- Legal compliance: Basic knowledge of copyright and anti-discrimination rules in AI-generated content.
- Human oversight: Knowing where AI can assist and where human decisions remain mandatory.
Article 4 and Deployer Obligations: What You Need to Know
Article 4 of the EU AI Act lays the foundation for competent use of artificial intelligence. The regulation explicitly requires deployers to ensure that people operating AI systems have a sufficient level of AI competence.
The principle of proportionality applies here: training measures must match the risk and context of the AI system being used.
- Low risk (e.g., text generation, internal research): Basic training and refreshers are sufficient here.
- High risk (e.g., AI in HR for candidate selection): Here, significantly stricter requirements apply to subject-matter expertise and complete documentation of training.
The AI Act formulates an outcome-oriented obligation. It doesn't prescribe how the training must look — but it does require that it took place and was appropriate.
Why Guidelines Alone Are No Longer Enough
Many companies introduced AI policies in 2023 and 2024. These contain important basic rules (e.g., "Don't enter customer data into public AI tools"). Such guidelines are an important foundation — but they don't create demonstrable competence.
When audits or quality reviews raise the question of how AI competence is ensured within the team, pointing to a PDF sent by email is legally and organizationally insufficient. The EU AI Act calls for an active process:
- Active knowledge transfer: Content must be presented clearly and actually taught.
- Comprehension checks: It must be verifiable that the key points were understood.
- Currency: Since AI technology evolves rapidly, training must be updated regularly.
Structured training with practical examples ensures a consistent minimum level throughout the company and gives employees real confidence in their day-to-day actions.
Building Structured AI Training: The Key Components
A compliance-ready training concept can be built in a modular and flexible way. In practice, the following components have proven effective:
1. Foundational Module (for All Employees)
- How AI works (opportunities and limitations)
- Overview of tools approved for use in the company
- Typical risks (hallucinations, bias, data protection)
- Overview of internal AI guidelines
2. Role-Specific Deep Dives
- HR / People teams: Special due diligence obligations regarding personal data, avoiding discrimination risks from AI-based pre-screening.
- Marketing & sales: Copyright for AI-generated images/text, data protection in customer communication.
- IT & compliance: Technical interfaces, containing shadow AI, monitoring data flows.
3. Simple Knowledge Checks
A short quiz or reflection questions (e.g., 5 multiple-choice questions at the end of a module) help confirm that the most important dos and don'ts were understood.
Documentation and Record-Keeping Requirements: What You Need to Archive
For compliance purposes, being able to prove that training took place is essential. A structured overview takes the complexity out of the process. The following data should be recorded:
| What is documented? | Concrete evidence in practice | Recommended retention |
|---|---|---|
| Attendance & date | System log (LMS) or digital sign-off list | At least 3 years |
| Training content | Retention of presentation slides or curriculum | At least 3 years |
| Successful completion | Test result (passed/failed) or certificate | At least 3 years |
Whether you use an existing learning management system (LMS) or a simple, centrally maintained matrix (e.g., in Notion or Excel) is up to you. What matters is complete traceability.
Special Considerations for SMEs: Pragmatic Solutions Without a Huge Budget
The good news: you don't need a six-figure budget to meet the EU AI Act's requirements. Small and medium-sized businesses in particular can tackle this in an agile and cost-effective way:
- Use internal champions: Identify AI-savvy employees on your team to act as "AI champions." They can pass on internal knowledge and serve as the first point of contact for questions.
- Use micro-learning: Instead of multi-day classroom training, compact 30- to 60-minute e-learning modules are often enough and are easy to fit into the workday.
- Hybrid approach: Use standardized external online courses for the legal and technical basics, and supplement them with a short internal meeting to discuss your specific tools.
Practical Tips: How to Get Started with AI Compliance Training
A pragmatic roadmap for implementation in your company:
- Take stock: Which AI tools are already actively in use (both officially approved tools and unofficial "shadow AI")?
- Assess risk: Which departments carry the highest risk (e.g., where a lot of sensitive data is handled)? Start there first.
- Define a concept: Create a short baseline module for everyone and plan specific updates for individual departments.
- Communicate: Explain the "why" to your team. Make clear that the training isn't a bureaucratic hurdle, but gives employees confidence in using innovative tools.
Common Implementation Mistakes to Avoid
- Starting too theoretically: Avoid long lectures on the history of AI. Focus on concrete use cases from your teams' everyday work.
- Treating it as a one-off instead of a process: AI evolves rapidly. Plan short updates from the outset — e.g., annually — to respond to new tool features or legal changes.
- Leaving out leadership: Executives and department heads also use AI and make strategic decisions based on AI-generated data. They should complete the training just like everyone else.
Conclusion
The EU AI Act turns AI literacy from a nice-to-have into a requirement. Text-only guidelines are no longer enough — structured, demonstrable training processes are now called for. For companies, though, this is no cause for concern, but a genuine opportunity: by training their teams deliberately, they minimize error sources, ensure legal certainty, and make full, productive use of the potential of ChatGPT, Copilot, and similar tools. With pragmatic modules and digital documentation, implementation is entirely manageable for SMEs too.
FAQ
Do employees who only use AI privately need to be trained, too?
Do employees who only use AI privately need to be trained, too?
The obligation under the AI Act refers to professional use on behalf of the company. A short basic training for the entire workforce is still advisable, however, to raise awareness of the risks of "shadow AI" (e.g., carelessly entering internal information into private accounts).
Are there official certificates we need to obtain?
Are there official certificates we need to obtain?
No. The EU AI Act doesn't prescribe any specific government certificate. What matters is that the training measure demonstrably took place and was appropriate to the risk level of the tools used.
Who is liable if a trained employee still makes a mistake?
Who is liable if a trained employee still makes a mistake?
Training is a central part of the so-called exculpatory evidence. It shows authorities and auditors that the company has fully met its legal duty of care and has taken organizational precautions.
How can heyData support you with this?
How can heyData support you with this?
heyData takes the complexity of implementation off your shoulders. You get legally sound, ready-to-use AI compliance trainings specifically tailored to the requirements of the EU AI Act. The modules are compact, practical, and include an integrated comprehension check.







