AI & Work

AI literacy and AI Act mandatory training: how to do it in the company

5 min read
AI literacy and AI Act mandatory training: how to do it in the company

The AI Act’s AI literacy duty does not require a university course for everyone: it requires proportionate measures so that people who use AI systems at work do so with awareness. It has applied since 2 February 2025 and covers providers and deployers.

General information, not legal advice.

What Article 4 actually says

Article 4 of the AI Act requires providers and deployers to take measures, to the best extent, to ensure a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf. Account must be taken of:

  • technical knowledge, experience, education, and training;
  • the context in which the systems are used;
  • the persons or groups on whom the systems may be used.

The definition of AI literacy is in Article 3, point 56: skills, knowledge, and understanding that allow informed deployment of AI systems and awareness of opportunities, risks, and possible harm.

Operational translation: it is not enough to “have done a webinar on ChatGPT.” People need to understand limits, data, output verification, and when not to use the tool.

Why it also covers those who “only use Copilot”

Many SMEs think literacy is only for people who build models. The text says otherwise: it also covers deployers, i.e. those who use AI systems in a professional context.

If sales pastes client briefs into a generative tool, if HR uses an assistant for screening, if operations asks an agent to update tickets: that is operation and use of AI systems. The literacy duty applies in proportion to the role, not only to engineers.

In Italy, Law 132/2025 reinforces training in specific areas (e.g. labour observatory, training measures in public administration), but the European baseline remains AI Act Art. 4.

How to structure training without a huge budget

An effective SME path is short, repeated, and tied to real work. Not a course catalogue.

  1. Map roles and uses: who uses which tools, on which data, at what risk.
  2. Write minimal rules (1–2 pages): what can and cannot be uploaded; when human oversight is required.
  3. Hands-on sessions of 60–90 minutes on a real team use case.
  4. A concrete task in the following days + feedback.
  5. An internal champion for questions and escalation.
  6. Periodic check: has use changed? Are typical errors down? Is Shadow AI down?

This approach matches how we build literacy at Zendata: less theory, more correct habit. We also cover it in Training people on AI without huge budgets.

What to teach first (and what to postpone)

Immediately:

  • what your tool can and cannot do on the real process;
  • how to verify sources, numbers, and decisions;
  • rules on personal data and confidential documents;
  • when to stop and ask a responsible human;
  • how to recognise plausible but wrong outputs.

Later:

  • model architecture;
  • provider comparisons;
  • advanced prompt engineering for its own sake.

The goal is not to train AI engineers. It is to reduce errors, leakage, and hidden uses.

How to show you did something serious

There is no single mandatory European “magic certificate” for all SMEs. What helps in audit and internal governance is having a trail of:

  • tool inventory and training audience;
  • shared materials and rules;
  • session dates and participants;
  • updates when tools or processes change;
  • a link to ownership and escalation (accountability).

If training exists only as a PDF deck nobody opened, it is not literacy: it is theatre.

FAQ

Has AI Act training been mandatory since 2025?
The duty for providers and deployers to take AI literacy measures has applied since 2 February 2025, according to the Art. 4 / Art. 113 AI Act timeline.

Do we need an official certified course?
The regulation asks for a sufficient, proportionate level—not a specific course brand. Effectiveness and fit to the use context matter.

Is a one-off webinar enough?
Usually no. Continuity and a link to real work are needed; otherwise adoption does not change and Shadow AI grows.

Are literacy and data security the same thing?
No, but they reinforce each other. Literacy without data rules is incomplete; rules without training get bypassed.

Sources

Dig deeper in the series

If you want to design an AI literacy path targeted to a team and a concrete use case—short, measurable, and aligned with Art. 4—we can build it together. Write to info@zendata.it or visit zendata.it.

Pietro Ciattaglia, CEO of Zendata AI, Rome