Article 4 AI Literacy: a One-Page Training Plan for a Small Company (in Force Since February 2025)
By the end of this post you will have a four-session AI literacy plan for your team, the record that documents it, and the material for the first session. Everything is free. The only hardware is the laptop you run the sessions from, and the live demo works on a machine with 8 GB of RAM.
What you need
- A list of the AI tools people in your company actually use: chat assistants, code assistants, the features inside your CRM or accounting software, and any model you run locally.
- One hour to plan, then four sessions of 45 to 60 minutes spread over a month.
- Free sources: the Commission’s AI literacy questions and answers, its living repository of AI literacy practices, and the AI Act Explorer on the Single Information Platform.
- Optional, for the demo:
ollama run llama3.1:8bor, on a smaller machine,ollama run qwen2.5:3b.
What Article 4 asks, in one paragraph
Article 4 of Regulation (EU) 2024/1689 has applied since 2 February 2025. It asks providers and deployers of AI systems to take measures so that their staff, and anyone operating AI on their behalf, have a sufficient level of AI literacy, taking into account their technical knowledge, experience, education and the context of use (EUR-Lex). The Digital Omnibus, Regulation (EU) 2026/1744, in force since 27 July 2026, rewrote the article as an obligation of effort: you must take measures to support the development of AI literacy, and the text now states that this does not require guaranteeing a specific level for any individual (EUR-Lex; analysis at lawandtechnology.eu). The Commission’s Q&A adds three practical points: no certificate is required, an internal record of trainings is enough, and there is no obligation to test employees. Supervision sits with national market surveillance authorities from August 2026; in Spain that is AESIA.
So the deliverable is small: a plan proportionate to your tools and roles, delivered, and written down.
Step 1: Inventory the tools and the people (15 minutes)
One row per tool. Be honest about the unofficial ones; they are the ones people need training on most.
| Tool | Who uses it | For what | Personal data involved? | Risk tier |
|---|---|---|---|---|
| Chat assistant in the browser | Everyone | Drafting emails, summaries | Sometimes | Minimal, Art. 50 disclosure when clients read the output |
| Code assistant | Two developers | Code, tests | No | Minimal |
| Local model on the office server | Sales, admin | Classifying invoices, RAG over manuals | Yes, supplier data | Minimal |
| Screening feature in recruitment software | HR | Ranking CVs | Yes | High-risk, Annex III point 4 |
If a row says high-risk, the deployer duties of Article 26 apply on top of this plan, including specific training for the people who exercise human oversight. Our risk classification guide helps you fill the last column.
Step 2: Assign a level to each role (10 minutes)
| Level | Who | Sessions |
|---|---|---|
| Foundation | Everyone, including part-time staff and contractors who use your tools | 1 and 2 |
| Practitioner | Anyone who uses an AI tool weekly for work that reaches a client, a candidate or a ledger | 1 to 3 |
| Oversight | Owner, managers, IT, whoever supervises a high-risk system | 1 to 4 |
Step 3: The four-session plan
This is the one page. Copy it, change the names, and it is your plan.
| Session | Audience | Length | Content | Exercise | Evidence kept |
|---|---|---|---|---|---|
| 1. What AI is and is not | Everyone | 45 min | How a language model predicts text; why it invents facts; what a token, a prompt and a context window are; the three house rules (verify, do not paste secrets, say when AI wrote it) | Live demo: ask a local model five questions about your own company and count the invented answers | Attendance list, slides, the five questions and answers |
| 2. Our tools and our rules | Everyone | 45 min | The inventory from Step 1; which data may go into which tool; where the local model runs and why; how to report a doubt or a mistake | Each person classifies three real tasks from their week as “allowed”, “allowed with review” or “not with AI” | Attendance list, the tool table, the reporting channel |
| 3. Checking AI output in your job | Practitioners | 60 min | Source check, number check, bias check, and how to document an override | Everyone brings three real outputs from the last month and reviews them with the checklist | Attendance list, the checklist, three anonymised reviews |
| 4. Obligations and oversight | Oversight group | 60 min | Risk tiers and the December 2027 date for Annex III; Article 26 deployer duties; Article 14 oversight; the incident path; the annual review date | Walk one high-risk or client-facing use through the Article 14 guide and write the stop procedure | Attendance list, the stop procedure, the review date |
Session 1 is where a local model earns its place. On our workstation llama3.1:8b answers at 37.8 tokens per second (measured 2026-09-08), so a wrong answer about your company’s founding year or your product range arrives in seconds, in front of everyone, and nobody forgets the lesson. On a 16 GB laptop the same demo runs at 5 to 10 tokens per second, which is still fast enough for a room.
Step 4: Keep the record (5 minutes per session)
The Commission says an internal record is sufficient. This table is the record.
| Date | Session | Trainer | Attendees | Materials (file names) | Next review |
|---|---|---|---|---|---|
| 2026-09-16 | 1. What AI is and is not | J. Gonzalez | 11 of 12 (M. Ruiz absent, catch-up 23-09) | s1-slides.pdf, s1-demo-questions.md | 2027-09 |
Store it next to your data protection records. New hires get sessions 1 and 2 in their first month; add a row.
Step 5: Review once a year, or sooner
Re-run the inventory when you adopt a tool, when a tool gains an AI feature, or when the Commission publishes new practical examples on the Single Information Platform. The living repository is explicitly not a safe harbour (replicating its practices “does not automatically grant presumption of compliance”), but it is the best free source of what other companies actually do.
Build the materials with a local model, in 20 minutes
You do not need to write quiz questions by hand. Run this on your machine:
ollama run qwen2.5-coder:7b "Write 10 multiple-choice questions, 4 options each, one correct, \
for a 45-minute introduction to AI for office staff at a small Spanish company. Cover: what a language \
model does, why it invents facts, which data must never be pasted into an online assistant, and \
when clients must be told they are reading AI output. Mark the correct answer and add a one-line explanation."
Read every question before you use it. In our runs the model produces usable questions and the occasional wrong “correct” answer, which is itself a good slide for session 1.
Honest limits
- This plan satisfies Article 4 for a company whose tools are minimal-risk. If you deploy a high-risk system, the oversight staff need deeper, system-specific training under Articles 14 and 26, and the provider must give you instructions for use to train from.
- Literacy does not make a tool compliant. Session 2 is where you discover the shadow tools; the follow-up is a policy, not another session.
- Attendance is evidence of effort, which is what the amended article asks. It is not proof that anyone learned anything, and the Commission does not ask you to prove that.
Next steps
- Fill the risk-tier column: AI risk classification under the EU AI Act.
- Write the stop procedure for session 4: Human oversight, Article 14.
- See the full calendar of obligations: EU AI Act compliance guide 2026 and our EU AI Act hub.
- Grab the template: AI literacy training plan (Article 4).
- Grab the template: AI risk classification worksheet.
Work with us
We deliver sessions 1 and 3 on site in Valencia and remotely, with the live demo running on a machine we bring or on yours, and we leave you the record filled in. If that saves you a week, get in touch or see how our consulting works.