Article 4 of the AI Act does not require every employee to become an AI expert. It requires companies to take reasonable measures so that people using AI on their behalf understand the technology they work with, its limitations and the risks relevant to their role.

This guide focuses on deployers – companies that use AI systems under their authority in their day-to-day activity. This includes SMEs using generally available AI tools, but also organizations integrating AI into HR, finance, customer service, legal, operational or other internal processes.

  1. Audit AI use

Identify the AI systems actually used, their purpose, the employees or contractors using them and the information processed through them.

Include both AI systems formally implemented by the company and tools employees use independently, such as ChatGPT, Copilot or other AI assistants. The result should be a simple AI inventory showing the tool, purpose, users and relevant risks.

  1. Asses the risks - Group employees according to their AI use

Consider what can go wrong in each use case: disclosure of confidential or personal data, inaccurate outputs, intellectual property issues, discrimination, automation bias or excessive reliance on AI.

Not everyone needs the same level of knowledge. A useful starting point is to distinguish between:

  • General users – employees using generative AI for drafting, research, translation or summaries.
  • Professional users – employees integrating AI into HR, legal, finance, customer service or other business processes.
  • Specialised or higher-risk users – persons operating or supervising AI that can affect recruitment, employees, credit, healthcare, safety or other individual rights.
  1. Define what each group needs to know

Training should reflect the risks connected to each role. Avoid one-size-fits-all training. Employees should know which AI tools they may use, what they may input, what they must verify, what decisions cannot be delegated to AI and when they must escalate an issue. Define clearly who reviews outputs, approves sensitive uses and handles incidents.

General users may need guidance on confidentiality, personal data, intellectual property, hallucinations and verification of outputs.

Employees using AI in more sensitive processes should also understand human oversight, discrimination, system limitations and applicable procedures.

  1. Implement simple measures

Depending on the organization, AI literacy measures can include:

  • a short AI policy;
  • practical training;
  • rules for approved and prohibited AI uses;
  • tool-specific instructions;
  • verification procedures;
  • periodic updates when new AI tools are introduced.

There is no mandatory training format or certification under Article 4. The internal rules should clearly allocate responsibilities: who may use which AI tools, who verifies outputs, who approves sensitive uses, who handles incidents and who is responsible for escalation.

  1. Document and update

Maintain the AI inventory, internal guidelines, training materials, attendance records and relevant employee communications. The Commission confirms that no certificate is required and that companies can document compliance through internal records of training and other guidance measures. Then revisit the exercise when the company introduces a new AI system or significantly changes how an existing system is used.

For SMEs, AI literacy does not need to become another heavy compliance exercise. Start small: know your AI, know your users, identify the relevant risks, give people practical guidance and document what you have done.