Skip to content
Confir.
Obligations & Roles

How to Run an AI Literacy Training Programme: A 12-Month Operating Plan for Article 4

Guide30 July 2026· 14 min read

A practical operating plan for an Article 4 AI literacy programme: a role-tier curriculum, delivery channels, and a 12-month onboarding-and-refresh cadence.

You already accept the duty. Now you have to run it — month after month, for new joiners and old hands alike, in a way you can show an authority. This is the operating manual, not the obligation explainer.

Article 4 of Regulation (EU) 2024/1689 has applied since 2 February 2025 and was not deferred by the Digital Omnibus provisional agreement of 6-7 May 2026. It binds every provider and deployer that places or uses AI on the EU market, regardless of risk tier. The questions this page answers are operational: who teaches what, how it is delivered, and how often it repeats.


From Obligation to Operating Programme: What This Page Covers

What Article 4 fixes and what it leaves to you

Article 4 fixes the duty: providers and deployers must take measures to ensure a sufficient level of AI literacy among staff and persons operating AI systems on their behalf. It is outcome-basedArticle 3(56) defines AI literacy as the skills, knowledge and understanding needed for informed deployment and awareness of the opportunities and risks. The Regulation prescribes no curriculum, no contact hours and no certificate, so the design choices below are illustrative, not mandated: a defensible way to meet the outcome, not the only way. What the Act leaves to you is everything operational — the curriculum, the channels, the cadence, and the records that prove it ran.

How this operating plan complements the obligation, policy and evidence guides

This page assumes the duty is settled and the tiers are defined. If they are not, four companion pages cover the upstream work, and this page does not repeat them: the EU AI Act Article 4 obligation explained; the AI literacy training requirements explainer; the AI literacy policy template; and the evidence file at how to prove AI literacy compliance. Start there if the obligation or tiers are not yet defined.


Step 1 — Set the Programme Foundations Before You Teach Anything

Appoint the owner and the sponsor

Name one accountable programme owner — typically the AI governance lead or compliance officer — and confirm a reporting line to a board-level sponsor. Article 4 measures must be demonstrable, and someone has to own the cadence, the records and the content reviews. The sponsor matters because Article 26 deployer duties and Article 99 penalty exposure put this on the board's risk map.

Drive scope from the AI inventory, not headcount

You cannot scope literacy until you know which systems exist, who operates them, and how each is classified under Article 6 and Annex III. Anchor the programme to your AI inventory, then map each system to the roles that build, deploy, oversee or are affected by it. That mapping turns the proportionality factors Article 4 names — technical knowledge, experience, education, training and context of use — into concrete audiences.

Calibrate depth to risk: deeper content where systems are high-risk (Annex III point 4 employment, point 5(b) creditworthiness), lighter where systems are limited or minimal risk. Set the success measure up front — completion plus a comprehension check — because the running programme is what produces the audit trail.


Step 2 — Build the Role-Tier Curriculum (Who Learns What)

The four tiers and their learning objectives

Resist a single all-staff module. Article 4's proportionality test calls for tiers calibrated to role:

  • Decision-makers and sponsors — the Act in plain terms, risk-tier literacy, why Article 26 deployer duties and Article 99 penalties create board-level exposure, and how to ask the right approval questions before signing off a deployment.
  • Builders and technical teams — model limitations, data quality, logging, and the technical underpinnings of the human-oversight design that Article 14 requires for high-risk systems.
  • Deployers and operational users — HR shortlisters, loan officers, drafters: what their specific system can and cannot reliably do, its known limitations, when and how to override, and the escalation path.
  • All-staff baseline plus transparency awareness — recognising AI interactions and the Article 50 disclosure duties (chatbot disclosure, deepfake and synthetic content labelling, with machine-readable content-marking duties from 2 December 2026 under the now-adopted Digital Omnibus).

Curriculum content blocks: the Act, risk tiers, human oversight, and your own systems

Express each tier as concrete modules and learning objectives so the curriculum is build-ready, not abstract. Four content blocks recur across tiers at different depths: the Act and your obligations; the risk-tier model under Article 6 and Annex III; the human-oversight competence Article 14 presupposes; and — most important for operational users — your own named systems, taught as the tool in front of them.


Role-Tier Curriculum and Cadence Matrix

Use this as a copy-and-adapt planning artefact: populate the rows against your own inventory, then schedule from it. Depth and refresh frequency rise with the risk exposure of the systems each tier touches.

Role tierExample rolesCore curriculum modulesDelivery formatComprehension checkInitial durationRefresh interval
Decision-makers / sponsorsBoard sponsor, risk officers, approversThe Act in plain terms, risk tiers, Article 26 duties, Article 99 exposureLive briefingScenario sign-off90 minAnnual
Builders / technicalData scientists, ML engineers, integratorsModel limitations, data quality, logging, Article 14 oversight designWorkshop + labDesign-review taskHalf dayAnnual
Deployers / operational usersHR shortlisters, loan officers, draftersWhat this system can and cannot do, override, escalationSystem walkthroughOverride exercise60-90 min6 months (high-risk)
Oversight / compliance staffHuman-oversight assignees, auditorsArticle 14 competence, Article 26 duties, evidence captureWorkshopAssessed taskHalf dayAnnual
All-staff baselineEvery employee and contractorRecognising AI, Article 50 transparency, confidentiality, escalationSelf-paced moduleShort quiz30-45 minAnnual

Read the rows as competence depth, not job title. Each tier's depth ties back to the Article 4 proportionality factors; the high-risk operator and oversight rows also carry the Article 14 oversight-competence requirement, which is why their checks are hands-on.


Step 3 — Choose Delivery Channels and Formats That Fit Each Tier

Format by tier: workshops, self-paced modules, system walkthroughs

Match format to tier. Live workshops or briefings suit sponsors and high-risk operators, where discussion carries the learning. Self-paced modules with an assessment suit the all-staff baseline, where reach and consistency matter more than dialogue. Hands-on, system-specific walkthroughs suit deployers of named tools, who need to drive the actual interface, not hear AI theory. Article 4 imposes no contact hours, no e-learning mandate and no certification scheme, so format is a design choice optimised for retention and for producing a record.

Embed system-specific micro-training at the point of deployment. Literacy for operational users is about the tool in front of them — the route optimiser, the screening system — so the most durable training arrives when they first get access.

Why every module needs a comprehension check

Build a comprehension check into every tier so completion produces defensible evidence rather than a sign-in sheet. A check can be a short quiz for the baseline, a scenario sign-off for sponsors, or an override exercise for operators — the point is a recorded result. Capture delivery, attendance and assessment results in a consistent register or LMS so the evidence accrues automatically as the programme runs.


Step 4 — Run the 12-Month Cadence: Onboarding and Refresh

Onboarding: train before operate

Treat onboarding as a hard gate. Anyone who joins, changes role into an AI-operating function, or is newly assigned to a system must complete the relevant tier before operating it — Article 4 reaches persons acting on the deployer's or provider's behalf, so the rule applies equally to contractors and temporary staff.

Annual baseline plus event-driven refresh triggers

Make an annual refresh the default rhythm, with shorter intervals for high-risk system operators. On top of the calendar, run event-driven refreshes when:

  • a new system enters the inventory;
  • a system undergoes a substantial modification, which under Article 25 can turn a deployer into a provider;
  • a regulatory change lands; or
  • a material incident occurs.

A quarterly checkpoint calendar

Give the year four checkpoints so the cadence does not slip:

  • Q1 — inventory reconciliation: confirm the systems and roles the programme covers still match reality.
  • Q2 — completion audit: chase outstanding modules and comprehension checks.
  • Q3 — content review against any legal updates, including the moving Article 50 content-marking date.
  • Q4 — governance sign-off: the owner reports completion and gaps to the sponsor.

Document the cadence itself — review minutes and a refresh schedule — because the recurrence is part of what makes the programme demonstrable.


Step 5 — Let the Running Programme Produce Its Own Evidence Trail

The records the cadence generates automatically

A well-run programme produces evidence as a byproduct: the role-to-system mapping, the curricula, attendance and completion logs, comprehension results, onboarding and refresh records, and governance review minutes. Wire record capture into delivery rather than reconstructing it later — a failure to keep evidence is what converts an open-textured duty into a finding. Connect those records to adjacent obligations, Article 14 oversight and Article 26 deployer duties, so the programme supports one coherent compliance file.

Who supervises and what they ask for

Article 4 supervision sits with national market-surveillance authorities, which member states designate under Articles 70 and 74. Do not assume a specific authority name — confirm the designated authority in your member state. These are the bodies that would ask to see the trail. For the full artefact set, see the dedicated how to prove AI literacy compliance guide.


Worked Example: Running the Programme at a 250-Person Logistics Company

Scoping tiers from a three-system inventory

Meridian Freight, a 250-person EU logistics operator, runs three AI systems: a third-party route-optimisation tool, an internal FAQ chatbot, and a recruitment screening system that falls under Annex III point 4 and is therefore high-risk. The Head of Compliance owns the programme; the COO is the sponsor.

From that three-system inventory she scopes the tiers. Depth is heaviest for the recruitment-tool operators — three HR shortlisters — given the high-risk classification and the Article 14 oversight competence their role demands. The route tool draws a builder tier for the four-person data team integrating it; the chatbot and general AI exposure sit in the all-staff baseline; the COO is in the decision-maker tier.

First-quarter rollout and the 12-month cadence in action

The first quarter rolls out in sequence: a 90-minute sponsor briefing for the COO and approvers; a 40-minute self-paced baseline module for all 250 staff, including the Article 50 transparency points for the chatbot; a system walkthrough for the HR shortlisters with override training tied to Article 14; and a half-day builder session for the data team integrating the route tool.

Over the year the cadence runs: an annual baseline refresh, quarterly completion audits, and — when a new demand-forecasting tool enters the inventory in Q3 — an event-driven refresh for the planners who will operate it. After one cycle, the programme has produced the role-to-system map, completion and comprehension logs, the HR override-exercise results, and four sets of governance minutes — without Meridian standing up a separate compliance project. The figures are illustrative, not mandated thresholds.


How Confir Helps

Confir links your AI inventory to role-tier literacy scoping, so the programme stays driven by the systems actually in use rather than a static org chart. It tracks delivery, completion, comprehension checks, onboarding triggers and refresh cadence in one register — the demonstrable record Article 4 expects — and maps those records to adjacent obligations (Article 14 oversight, Article 26 deployer duties) inside a single compliance file.

The synthesis engine is deterministic and rule-based: the same inventory and role mapping produce the same scoping and the same refresh triggers every time — no model inference, no hallucination. Confir surfaces refresh and onboarding due dates so the cadence runs on schedule; it does not generate or grade training.


Frequently Asked Questions

How is this different from a guide on building an AI literacy programme?

A build guide explains the obligation and the structure: what sufficient literacy means and the four role tiers. This page is the operating manual for running that programme once it exists. It focuses on the recurring mechanics, namely delivery channels per tier, onboarding triggers, an annual-plus-event-driven refresh cadence, and a quarterly checkpoint calendar. Think of it as the difference between designing the curriculum and operating the timetable. If you have not yet defined the obligation or the tiers, start with the build guide, then return here to keep the programme running and current.

How often should AI literacy training repeat under Article 4?

Article 4 of Regulation (EU) 2024/1689 sets no fixed interval, so cadence is a proportionality choice. A practical default is an annual baseline refresh for all staff, with shorter cycles for operators of high-risk systems such as recruitment tools under Annex III point 4. On top of the annual rhythm, run event-driven refreshes: a new system entering your inventory, a substantial modification, a regulatory change, or an incident. Document the schedule and review minutes, because the recurrence itself is part of what makes the programme demonstrable to a supervising authority.

Who should own the AI literacy training programme?

Name a single accountable owner, typically the AI governance lead or compliance officer, with a reporting line to a board-level sponsor. Article 4 requires demonstrable measures, so someone must own the cadence, the records, and the content reviews. The owner scopes tiers from the AI inventory, schedules onboarding and refreshes, and signs off at quarterly checkpoints. The sponsor matters because deployer duties under Article 26 and the penalty exposure under Article 99 create board-level risk, and an owner without a sponsor rarely keeps the programme funded and current.

What delivery format does Article 4 require?

None specifically. Article 4 mandates no contact hours, no e-learning platform, and no certification scheme. Format is a design choice you should optimise for retention and for producing a record. In practice, live briefings suit sponsors and high-risk operators, self-paced modules with an assessment suit the all-staff baseline, and hands-on walkthroughs suit operational users of a named tool. Whatever you choose, build a comprehension check into every tier so completion produces defensible evidence rather than an attendance list, and capture results in a consistent register as the programme runs.

Does new staff onboarding need to include AI literacy training?

Yes, where they will operate AI systems. Article 4 covers persons operating AI systems on the provider's or deployer's behalf, so anyone who joins, moves into an AI-operating role, or is newly assigned to a system should complete the relevant tier before operating it. Treat onboarding as a hard gate: train before operate. The same rule applies to contractors and temporary staff who use your AI tools. Wiring this into your joiner process keeps the literacy register current automatically and avoids a gap between hiring and the next annual refresh cycle.

Does running a training programme automatically satisfy Article 4?

Running it is necessary but the records are what make it defensible. A well-run programme should generate its own evidence as a byproduct: role-to-system mapping, curricula, attendance and completion logs, comprehension results, onboarding and refresh records, and governance minutes. National market-surveillance authorities, designated by member states under Articles 70 and 74, are the bodies that would ask to see this trail. A failure to keep evidence is what converts the open-textured duty into a finding, so capture records inside delivery rather than reconstructing them when an authority asks.

Is the AI literacy obligation delayed by the Digital Omnibus?

No. Article 4 has applied since 2 February 2025 and is unaffected by the Digital Omnibus. The Omnibus, now adopted by the European Parliament (16 June 2026) and the Council (29 June 2026), concerns other timelines, such as deferring certain high-risk dates to 2 December 2027 and 2 August 2028; it enters into force on Official Journal publication, expected before 2 August 2026. Your literacy programme should be live now, not scheduled against a future deadline, and you should plan against the dates currently in force.


Manage your EU AI Act compliance in one place

Confir automates risk classification, technical documentation, and audit trails for any company. No consultants. No 6-month projects. 14-day free trial.

Start free trial →